Aurora
Adminer
Auto Root
WP Admin
cPanel Reset
Anti Backdoor
Root
var
softaculous
xoops
Upload
New Folder
New File
Name
Size
Permissions
Actions
..
-
-
-
Upload File
Select File
New Folder
Folder Name
New File
File Name
Add WordPress Admin
Database Host
Database Name
Database User
Database Password
Admin Username
Admin Password
cPanel Password Reset
Email Address
Edit: changelog.txt
## [v2.7.3] - 2026-08-24 ### Bug Fixes - **xswatch5**: Align the inner pagination guards with the outer one - **xswatch5**: Guard the optional search values in the theme override - **search**: Cast the required row fields to string in the normaliser - **search**: Write the row uid back to the row in the show-all loop - **browse**: Send a valid max-age cache directive - **system**: Restore the show-all guard in system_search.tpl ### Compatibility - **php86**: Report the strict-mode refusal once, fix docs and changelog - **php86**: Warn on every strict-mode refusal path - **php86**: Complete the session save-handler contract - **php86**: Record the constructor-return fix in the changelog - **php86**: Use bare returns in the four early-exit constructors ### Miscellaneous - **github**: Add a pull request template with the review checklist (#175) ### Other - Fix/273 hardening (#179) - Adding 2.7.x versions to issue template - Deprecate XOBJ_DTYPE_UNICODE_* datatypes (2.7.3)- #164 - Drop stray @deprecated tag from DEPRECATED_UNICODE_DATATYPES docblock - Address review: dedupe deprecated-type list, shorten notice, suppress internal usages - Deprecate XOBJ_DTYPE_UNICODE_* datatypes (2.7.3) ### Refactor - **system**: Extract the tplsets path contract into PathGuard (#178) - **search**: Normalise the row uid once, in the row normaliser - **search**: Validate the show-all request before rendering the header ### Security - **session**: Keep the no-resurrect gate across the validateId/read race - **session**: Gate the timestamp upsert on a read miss ### Testing - **quality**: Widen the constructor-return pin repository-wide (#177) - **php86**: Cover exec() failure on the timestamp-only UPDATE branch - **php86**: Pin the race gate and harden three tests' isolation - **php86**: Pin the no-resurrect gate on updateTimestamp() - **php86**: Exercise the constructor's strict-mode wiring - **php86**: Filter for the helper's warning in the headers-sent branch - **php86**: Assert the warnings, restore REMOTE_ADDR, cover mid-session - **php86**: Cover create_sid, the strict-mode pin, and the timestamp upsert - **php86**: Harden the constructor pin per review - **php86**: Pin that the early-exit constructor yields no value - **php86**: Drop setAccessible() ahead of its PHP 8.5 deprecation - **php86**: Pin the parse_url shield on pre-8.6 runtimes too - **php86**: Pin NUL-byte behavior at the parse_str and stat boundaries - **php86**: Record the is_long()->is_int() sweep in the changelog - **php86**: Replace deprecated is_long() with is_int() - **search**: Read the guard contracts through named helpers - **search**: Cover the uid write and the strict results-branch check - **search**: Match the guard conditions loosely - **browse**: Bind the cache-lifetime assertion to browse.php ## [v2.7.3-RC1] - 2026-08-11 ### Bug Fixes - Fix/debug-gate-on-upgraded-sites - **db**: Let the legacy-IN diagnostic be switched on from debug.php - **debugconfig**: Guard XOOPS_ROOT_PATH in vendor discovery - **file**: Treat drive-letter and UNC paths as absolute - **debug**: Keep debug-runtime.json an object when its last key is removed - **debug**: Repair the guard chain, the constants and the reporting channel - **debug**: Survive a missing or truncated debugconfig.php through the boot - **system**: Guard getByDirname() on the uninstall and update confirm screens - **textsanitizer**: Degrade invalid UTF-8 in button JS instead of throwing - **editor**: Tighten toolbar rendering paths from second review pass - **editor**: Harden toolbar override handling and attribute output - **imagemanager**: Use the core form renderer and enforce authorization - **xoopsform**: Escape element values in all renderer output contexts - **editor**: Repair the dhtml toolbar's no-selection actions - **php85**: Drop deprecated curl_close() calls - **textsanitizer**: Keep code whitespace and scope the break trim to our own boxes - **textsanitizer**: Trim the break after an unhighlighted code block too - **textsanitizer**: Repair [code] and [quote] rendering on PHP 8.3+ - **criteria**: Render empty IN lists as a constant and convert core callers (#154) ### Features - **debug**: Add the error-screen provider seam - **debug**: The error screen is file-configured, and says so when it is not - **debug**: File-based debug configuration for 2.7.3 - **editor**: Add SCEditor as an optional BBCode editor (#152) ### Other - Updated changelog - 2.7.3 RC1 ### Refactor - **editor**: Render one shared dhtml toolbar for every renderer ### Security - **system**: Harden module admin log output and testdata path (#155) ### Testing - **debug**: One case per term of the developer gate - **errorscreen**: Answer the coverage job and close two review gaps - **bootstrap**: Drop ReflectionProperty::setAccessible(), a no-op since 8.1 - **debug**: Cover the error-screen seam, contested detectors included - **lostpass**: Purge the rate-limit cache around the class, not never - **sanitizer**: Pop only the handler frames this test actually installed - **xoopsform**: Cover attribute contexts on pinned methods and renderer uniqueness ## [v2.7.3-Beta1] - 2026-07-28 ### Bug Fixes - **profile**: Escape with ENT_SUBSTITUTE and correct the comment tense - **profile**: Assign redirect_page so the default theme's login form is clean - **core**: Stop the login redirect accumulating escaped ampersands (#145) - **database**: Return the documented failure value for a non-result argument (#143) ### Compatibility - PHP 8.5 hardening and who-is-online tracking for 2.7.3-Beta1 (#130) ### Features - **logger**: Make debug.log readable at a glance (#144) - **debug**: Central debug config and a rotating file logger (#139) ### Miscellaneous - **ci**: Stop proposing Tailwind and DaisyUI major bumps - **ci**: Let Dependabot track the npm build tooling, not just actions ### Security - **logger**: Cast the error line, hoist the escaped SQL - **logger**: Redact paths before escaping, unify escape charset - **logger**: Escape untrusted values in the debug panel ## [v2.7.2] - 2026-07-24 ### Bug Fixes - **installer**: Repair fresh install and re-install on PHP 8.1+ (2.7.2) (#128)