<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket Query</title>
    <link>http://localhost:8080/trac/query?component=Unassigned&amp;milestone=Maintenance&amp;group=status&amp;desc=1&amp;order=summary</link>
    <description>Support and issues tracking for the Transition Network Web Project.</description>
    <language>en-US</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/query?component=Unassigned&amp;milestone=Maintenance&amp;group=status&amp;desc=1&amp;order=summary</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
        <link>http://localhost:8080/trac/ticket/676</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/676</guid>
        <title>#676: Alternative to Skype for TTech Meetings</title>
        <pubDate>Tue, 14 Jan 2014 13:33:51 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Jim has pointed out that:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Skype costs us 15-30 minutes of grinding pain every time we do this!
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
So what are the alternatives and what are our requirements?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/676#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/638</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/638</guid>
        <title>#638: Question about notifications option for content creators</title>
        <pubDate>Thu, 28 Nov 2013 12:32:57 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Content creators (news, Rob's blog, social reporters) struggle with the notifications. the problem is that they forget to click the option to 'do not send notifications for this update' and then notifications are sent out. It is easy for us to think this is easy for them, but when you are bashing stuff out in a hurry, it's easy to forget this fiddly bit.
&lt;/p&gt;
&lt;p&gt;
CAN WE set drupal to NOT send notifications out as standard for some of the content types?
&lt;/p&gt;
&lt;p&gt;
And change it so that the content creators (news, Rob's blog, social reporters) choose to SEND notifications out instead (of NOT sending them)
?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/638#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/711</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/711</guid>
        <title>#711: Emails &amp; Telephone calls</title>
        <pubDate>Tue, 01 Apr 2014 13:47:56 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description></description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/711#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/609</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/609</guid>
        <title>#609: Videos not showing if added via video link</title>
        <pubDate>Tue, 15 Oct 2013 08:33:43 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
e.g. of project profile:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/projects/new-forest-transition-school-community-energy-saving-project"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/projects/new-forest-transition-school-community-energy-saving-project&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
none showing on video page:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/video"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/video&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/609#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/562</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/562</guid>
        <title>#562: Users being subscribed to widgets newsletter on registratoin</title>
        <pubDate>Mon, 17 Jun 2013 15:11:22 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Ed added new users to system via user--&amp;gt;add user. They are being automatically subscribed to the widget owners newsletter. Please investigate and stop this.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/562#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/601</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/601</guid>
        <title>#601: TTech Meeting 3rd October 2013</title>
        <pubDate>Thu, 03 Oct 2013 09:03:42 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
This is a ticket for notes and times for the online meeting held on 3rd October 2013.
&lt;/p&gt;
&lt;p&gt;
The ticket for the last meeting is &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/585" title="maintenance: TTech Meeting 5th September 2013 (closed: fixed)"&gt;ticket:585&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/601#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/852</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/852</guid>
        <title>#852: TN site down</title>
        <pubDate>Fri, 15 May 2015 18:23:38 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi all
&lt;/p&gt;
&lt;p&gt;
According to pingdom and testing in my browser TN is currently unavailable.
&lt;/p&gt;
&lt;p&gt;
Is anyone around over the weekend to take a look?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/852#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/826</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/826</guid>
        <title>#826: Switching MX records from United to Google</title>
        <pubDate>Thu, 15 Jan 2015 17:15:41 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
TN are switching the MX records from United to Google on Friday 23/1/15.
&lt;/p&gt;
&lt;p&gt;
Will this affect the website/Web Architects in any way that we need to plan for in advance? Scripts, web forms etc? Anything you can think of?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/826#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/579</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/579</guid>
        <title>#579: Special email alert for Rob Hopkins blog posts on TN.org</title>
        <pubDate>Mon, 12 Aug 2013 13:49:30 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;ol&gt;&lt;li&gt;Can we create a specific email alert for new blog posts from Rob Hopkins' blog (/blogs/rob-hopkins)?
&lt;/li&gt;&lt;li&gt;Can Ed do this?
&lt;/li&gt;&lt;li&gt;See below:
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
Proposed new alert:
&lt;del&gt;&lt;/del&gt;&lt;del&gt;&lt;/del&gt;&lt;del&gt;&lt;/del&gt;&lt;del&gt;~
&lt;/del&gt;&lt;/p&gt;
&lt;p&gt;
From: [Rob Hopkins at Transition Network &amp;lt;site@…&amp;gt;]
Subject: New blog post from Rob Hopkins' Transition Culture
To: [subscriber email]
Reply to: [&amp;lt;site@…&amp;gt;]
&lt;/p&gt;
&lt;p&gt;
Hello. I've written a new blog Transition Culture blog post
&lt;/p&gt;
&lt;p&gt;
You can read it and leave comments here:
[LINK]
&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;
[BLOG POST TITLE]
[LINE BREAK - FULL CLEAR LINE]
[BLOG POST TEASER]
[LINE BREAK - FULL CLEAR LINE]
&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;
Best regards,
Rob
&lt;/p&gt;
&lt;p&gt;
--
[TN EMAIL SUBSCRIPTION AUTO-BLURB]
This is an automatic message from Transition Network
To manage your subscriptions, browse to &lt;a class="ext-link" href="http://www.transitionnetwork.org/user/285/notifications"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.transitionnetwork.org/user/285/notifications&lt;/a&gt;
You can unsubscribe at &lt;a class="ext-link" href="http://www.transitionnetwork.org/notifications/unsubscribe/subscription/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.transitionnetwork.org/notifications/unsubscribe/subscription/&lt;/a&gt;...
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/579#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/815</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/815</guid>
        <title>#815: Security updates need to be applied for a couple of contributed modules:</title>
        <pubDate>Tue, 16 Dec 2014 13:45:16 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description>&lt;p&gt;
DBTNG
Hierarchical Select
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/815#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/728</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/728</guid>
        <title>#728: Re-patch location module</title>
        <pubDate>Tue, 20 May 2014 12:53:16 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Bugger just realised that I didn't finish the pull request into the main branch: &lt;a class="ext-link" href="https://trac.transitionnetwork.org/trac/ticket/681"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://trac.transitionnetwork.org/trac/ticket/681&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
So the location module patch is not on the live site.
&lt;/p&gt;
&lt;p&gt;
I have now done the patch correctly I think: &lt;a class="ext-link" href="https://github.com/transitionnetwork/transitionnetwork.org-d6.profile/pull/2"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://github.com/transitionnetwork/transitionnetwork.org-d6.profile/pull/2&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Shall I additionally add the patch to the live site using Drush as I did before?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/728#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/566</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/566</guid>
        <title>#566: Profile photo does not work</title>
        <pubDate>Wed, 26 Jun 2013 14:17:35 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Using this user account:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/users/patricia-benson"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/users/patricia-benson&lt;/a&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/people/patricia-benson"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/people/patricia-benson&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
I can't get the photo to sit correctly. I have already deleted her first user account as the first photo she put in was sideways - the system presented that the right size, but sideways. Then I couldn't get the system to forget the original photo so had to delete the account and start again.
Now I've tried adding  bigger, smaller pictures and they all come out far too big - the system is enlarging them up to wider than the space alloted.
&lt;/p&gt;
&lt;p&gt;
Very odd. Too tired and busy to do this now - will revisit in July after holiday.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/566#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/600</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/600</guid>
        <title>#600: Numbers missing from Initiatives search page</title>
        <pubDate>Mon, 30 Sep 2013 11:46:20 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
When users do a search on /initiatives we are missing a number which pertains to the results of the report:
&lt;/p&gt;
&lt;p&gt;
It should say "XXX initiatives match your search criteria"
&lt;/p&gt;
&lt;p&gt;
The XXX bit is missing
&lt;/p&gt;
&lt;p&gt;
please check and resolve
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/600#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/553</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/553</guid>
        <title>#553: Invalid response from server ERROR message</title>
        <pubDate>Tue, 28 May 2013 15:13:43 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Trying to add a user. Get error message: "Received an Invalid response from the server" then served a blank screen. Same with project profile:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/user/user/create"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/user/user/create&lt;/a&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/node/add/project-profile"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/node/add/project-profile&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
This has also happened for a user trying to add a project.
&lt;/p&gt;
&lt;p&gt;
Ed can add an event and blog post, ingredient, panel page.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/553#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/560</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/560</guid>
        <title>#560: Install drupal-based project management system onto our servers</title>
        <pubDate>Tue, 11 Jun 2013 17:00:28 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Please can you install a suitable project management drupal-based tool onto the suitable server? I am thinking of Open Atrium. It's for staff and partners to use for management stuff (ie not a ticketing system or mediawiki).
&lt;/p&gt;
&lt;p&gt;
Open Atrium?
&lt;/p&gt;
&lt;p&gt;
Can you let me know how long it would take to install to a point where I can manage it and get a pilot project up and running?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/560#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/607</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/607</guid>
        <title>#607: Getting three copies of stats reports</title>
        <pubDate>Mon, 14 Oct 2013 08:27:59 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
I'm getting three copies of the stats reports (weekly) that I've set up here:
&lt;a class="ext-link" href="https://stats.transitionnetwork.org/index.php?module=PDFReports&amp;amp;action=index&amp;amp;idSite=1&amp;amp;period=day&amp;amp;date=today"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://stats.transitionnetwork.org/index.php?module=PDFReports&amp;amp;action=index&amp;amp;idSite=1&amp;amp;period=day&amp;amp;date=today&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Please investigate
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/607#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/705</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/705</guid>
        <title>#705: Create a contents page on TransitionCulture.org Wordpress site</title>
        <pubDate>Wed, 26 Mar 2014 15:33:43 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Create a contents page on TC.org to see a listing of all the blog posts. Mike suggests:
"use category post list widget to pull in the titles and then use widgetise pages to add widget to a standard page.:
&lt;/p&gt;
&lt;p&gt;
Sam to follow up. MAX time: 1 hour.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/705#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/565</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/565</guid>
        <title>#565: Blogs breadcrumbs incorrect on listings views</title>
        <pubDate>Tue, 25 Jun 2013 13:21:56 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Blogs breadcrumbs are wrong at main all blogs view and one author's full list view:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/blog"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/blog&lt;/a&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/blogs/ed-mitchell"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/blogs/ed-mitchell&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Jim can you sort this in under 15 minutes (which is what you have left)
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/565#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/630</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/630</guid>
        <title>#630: Archiving Transition Town Totnes site</title>
        <pubDate>Mon, 25 Nov 2013 11:54:35 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Please estimate to archive TTT site as per conversation with Ed:
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;convert to html
&lt;/li&gt;&lt;li&gt;host on Penguin (incl. any likely issues for Penguin doing this)
&lt;/li&gt;&lt;li&gt;any ongoing maintenance
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
Then Ed will discuss with Frances at TTT as per agreement with Chris
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/630#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/803</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/803</guid>
        <title>#803: Adding a CNAME value to TN.org zone files</title>
        <pubDate>Mon, 27 Oct 2014 16:14:09 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
I need to add a CNAME value to verify transitionnetwork.org for google apps.
&lt;/p&gt;
&lt;p&gt;
Can I do this on my own using the zone files in gandi or is it better that you do it Chris?
&lt;/p&gt;
&lt;p&gt;
The value will be automatically generated as part of the verification process for setting the apps up, so I'll need to add it promptly
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://support.google.com/a/answer/60216"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://support.google.com/a/answer/60216&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/803#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/684</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/684</guid>
        <title>#684: Adding Paul and Nick to Transition Network on github.org</title>
        <pubDate>Thu, 23 Jan 2014 10:42:23 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
It looks like Ed and Jim are the only one with permissions to add members to &lt;a class="ext-link" href="https://github.com/orgs/transitionnetwork/members"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Transition Network on GitHub&lt;/a&gt; as they are listed as owners and the rest of us are members.
&lt;/p&gt;
&lt;p&gt;
Paul and Nick can you post you account names to this ticket so you can be added?
&lt;/p&gt;
&lt;p&gt;
Jim could you make me and/or Ben owners as well so we can add people?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/684#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/643</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/643</guid>
        <title>#643: Add paginator for /films view</title>
        <pubDate>Mon, 09 Dec 2013 11:40:08 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Please add pages links for this view:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/build/views/edit/Films?destination=films#views-tab-page_1"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/build/views/edit/Films?destination=films#views-tab-page_1&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
10 per page should do it
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/643#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/744</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/744</guid>
        <title>#744: Add CSS Injector module to the D6 mix</title>
        <pubDate>Thu, 19 Jun 2014 10:50:03 GMT</pubDate>
        
        <dc:creator>annesley</dc:creator>

        <description>&lt;p&gt;
CSS Injector module allows admin dynamic adding of CSS in to a live production server without code updates. this is to respond quickly to client needs whilst implementing the requests in the correct place in the themes on the next promotion from dev.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/744#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/759</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/759</guid>
        <title>#759: [Security-news] SA-CONTRIB-2014-071 - FileField - Access bypass</title>
        <pubDate>Wed, 16 Jul 2014 21:59:46 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description>&lt;p&gt;
View online: &lt;a class="ext-link" href="https://www.drupal.org/node/2304561"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/node/2304561&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Advisory ID: DRUPAL-SA-CONTRIB-2014-071
&lt;/li&gt;&lt;li&gt;Project: &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; (third-party module)
&lt;/li&gt;&lt;li&gt;Version: 6.x
&lt;/li&gt;&lt;li&gt;Date: 2014-July-16
&lt;/li&gt;&lt;li&gt;Security risk: Critical &lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Exploitable from: Remote
&lt;/li&gt;&lt;li&gt;Vulnerability: Access bypass
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
The &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; module enables you to define and use fields that contain files.
&lt;/p&gt;
&lt;p&gt;
The module doesn't sufficiently check permission to view the attached file
when attaching a file that was previously uploaded. This could allow
attackers to gain access to private files.
&lt;/p&gt;
&lt;p&gt;
This vulnerability is mitigated by the fact that the attacker must have
permission to create or edit content with a file field.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;/A CVE identifier &lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; will be requested, and added upon issuance, in
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
accordance with Drupal Security Team processes./
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; 6.x-3.x versions prior to 6.x-3.13.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Drupal core is not affected. If you do not use the contributed &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt;
module, there is nothing you need to do.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;If you use the &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; module for Drupal 6.x, upgrade to Filefield
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
6.x-3.13 &lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt;, and also update to Drupal core 6.32 &lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt; (see
SA-CORE-2014-003 &lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt;).
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Ivan Ch &lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Nate Haug &lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Ivan Ch &lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;David Snopek &lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; of the Drupal Security Team.
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
The Drupal security team can be reached at security at drupal.org or via the
contact form at &lt;a class="ext-link" href="http://drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/contact&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Learn more about the Drupal Security team and their policies &lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt;, writing
secure code for Drupal &lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt;, and securing your site &lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Follow the Drupal Security Team on Twitter at
&lt;a class="ext-link" href="https://twitter.com/drupalsecurity"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://twitter.com/drupalsecurity&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/project/filefield"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/filefield&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team/risk-levels"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team/risk-levels&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; &lt;a class="ext-link" href="http://cve.mitre.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://cve.mitre.org/&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/project/filefield"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/project/filefield&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/node/2304517"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/node/2304517&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/drupal-6.32-release-notes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/drupal-6.32-release-notes&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/SA-CORE-2014-003"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/SA-CORE-2014-003&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/556138"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/556138&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/35821"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/35821&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/556138"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/556138&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/266527"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/266527&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/contact&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/writing-secure-code"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/writing-secure-code&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security/secure-configuration"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security/secure-configuration&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt; &lt;a class="ext-link" href="https://twitter.com/drupalsecurity"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://twitter.com/drupalsecurity&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;_
Security-news mailing list
Security-news@…
Unsubscribe at &lt;a class="ext-link" href="https://lists.drupal.org/mailman/listinfo/security-news"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://lists.drupal.org/mailman/listinfo/security-news&lt;/a&gt;
&lt;/span&gt;&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/759#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/857</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/857</guid>
        <title>#857: Tiny MCE weirdness</title>
        <pubDate>Tue, 02 Jun 2015 15:24:33 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Paul,
&lt;/p&gt;
&lt;p&gt;
Myself &amp;amp; Rob have both run into an intermittent issue where when editing a panel page the WYSYWG editor (Tiny MCE) sometimes appears, sometimes doesn't.
&lt;/p&gt;
&lt;p&gt;
When it doesn't appear you are left with the plain text html editor.
&lt;/p&gt;
&lt;p&gt;
There seems to be no obvious pattern to it. So might be a tricky one to debug.
&lt;/p&gt;
&lt;p&gt;
I see the version of Tiny MCE we are using is quite old, so I was thinking perhaps we should just try upgrading it on a dev server and see if that fixes it?
&lt;/p&gt;
&lt;p&gt;
If this seems reasonable could you stick the latest Tiny MCE on your dev server so we could test it out there? Or if you have any other ideas for getting to the bottom of it..
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/857#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/890</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/890</guid>
        <title>#890: Site offline.</title>
        <pubDate>Sat, 12 Dec 2015 10:54:36 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
It's serving a page, so may be Drupal level problem rather than server level?
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/890#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/671</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/671</guid>
        <title>#671: Replace core Search module with Apache Solr</title>
        <pubDate>Sat, 11 Jan 2014 21:11:14 GMT</pubDate>
        
        <dc:creator>jim</dc:creator>

        <description>&lt;p&gt;
&lt;strong&gt;Issue &amp;amp; background&lt;/strong&gt;
During work on &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/610" title="defect: Aegir database intensive (migrate, clone, restore) tasks hang for larger ... (closed: fixed)"&gt;#610&lt;/a&gt;, it was discovered that of a 1/4GB database dump for TN.org, ~80% (180Mb) of it was related to the Drupal 6 core Search module.
&lt;/p&gt;
&lt;p&gt;
It's worth noting &lt;a class="ext-link" href="https://tech.transitionnetwork.org/trac/ticket/516#comment:3"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;this&lt;/a&gt; was &lt;a class="ext-link" href="https://tech.transitionnetwork.org/trac/ticket/516#comment:6"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;raised&lt;/a&gt; when we migrated the site to the Puffin server in March 2013, but it's generally the case that the core Search module does not scale easily beyond a few thousand nodes.
&lt;/p&gt;
&lt;p&gt;
www.transitionnetwork.org has 23,803 nodes at time of writing -- this is probably approaching the sensible limit of the core module's capability.
&lt;/p&gt;
&lt;p&gt;
Note also, any future D7 or D8 version of the site would also hugely benefit from using Solr, so the server config part is time well spent.
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Proposed solution&lt;/strong&gt;
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;Add the Apache Solr option to BOA, re-run the installer to get it installed and configured automatically.
&lt;/li&gt;&lt;li&gt;Add the &lt;a class="ext-link" href="https://drupal.org/project/apachesolr"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;ApacheSolr module&lt;/a&gt; and any related required modules to the TN D6 makefile -- it's not clear if the 6.x-3.x branch or 6.x-1.x branch is the right choice at present.
&lt;/li&gt;&lt;li&gt;Build a new platform containing these modules, migrate a clone of STG to it.
&lt;/li&gt;&lt;li&gt;Enable the modules, configure them, disable core Search.
&lt;/li&gt;&lt;li&gt;Create a feature that wraps up config for Solr and required modules. Add to Git, add reference to feature to makefile
&lt;/li&gt;&lt;li&gt;Test, tweak, repeat 3 &amp;amp; 4 &amp;amp; 5 as needed.
&lt;/li&gt;&lt;li&gt;Migrate PROD to the new plaform, enabled feature, index site.
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
This could be parked until D7/8 migration, or not... Ed's call.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/671#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/764</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/764</guid>
        <title>#764: Policy decisions re-assessment on BOA and Drupal security updates</title>
        <pubDate>Tue, 22 Jul 2014 14:10:38 GMT</pubDate>
        
        <dc:creator>annesley</dc:creator>

        <description>&lt;p&gt;
on-line meeting 5 / August @ 14:00 GMT:
we are phasing out the current D6 / BOA system. the new system may not use either. The TN.org website is not attractive to high level hackers or DOS attacks.
&lt;/p&gt;
&lt;p&gt;
what are the risks with cancelling all further Unix, BOA and Drupal updates completely that do not allow direct un-mitigated access to the backend via bad PHP code / SQL?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/764#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/690</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/690</guid>
        <title>#690: Paul learning the ways of the force.</title>
        <pubDate>Thu, 20 Feb 2014 15:00:41 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description>&lt;p&gt;
I'm not a jedi yet
&lt;/p&gt;
&lt;p&gt;
#### Transition Network
&lt;/p&gt;
&lt;p&gt;
Week ending 16 February
Monday (0,45) Phone call | Emails (not issues) | Creating a test site on Aeigr
Tuesday (0.45) Reading Wiki pages | Setting up local server (Generated notes for WIki)
Wednesday (0.45) Reading wiki pages: setting up a platform / cloning a stage site.
Friday (3.00) Reading wiki pages , listening to Jim's talks,  Emails (not issues). (Generated notes for WIki for setting up a local server)
&lt;/p&gt;
&lt;p&gt;
Finished reading wiki. I'll re-read these as required on my own time going forward.
&lt;/p&gt;
&lt;p&gt;
Week ending 23 February
Monday (0,15) Emails (not issues) (Mailing list)
Thursday (0,30) Phone call / Emails (not issues)
&lt;/p&gt;
&lt;p&gt;
Total 6, 00 hours
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/690#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/804</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/804</guid>
        <title>#804: Investigating the site security following SA-CORE-2014-005 (Drupal 7.32)</title>
        <pubDate>Mon, 03 Nov 2014 15:20:25 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description>&lt;p&gt;
It was discovered that TN could have have been compromised from the recent security vulnerability (even though we are running Drupal 6)
as the site is using the DBTNG module. However the site doesn't appear to have been compromised. I'll post my findings shortly.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/804#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/856</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/856</guid>
        <title>#856: Blocked IP?</title>
        <pubDate>Tue, 02 Jun 2015 13:12:52 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Chris
&lt;/p&gt;
&lt;p&gt;
I was trying to SSH into the site and got my password wrong a couple of times.
&lt;/p&gt;
&lt;p&gt;
Shortly afterwards the site appeared to be unavailable from this location.
&lt;/p&gt;
&lt;p&gt;
It seems fine in pingdom/proxy servers.
&lt;/p&gt;
&lt;p&gt;
My guess is something like fail2ban or similar has added this IP to a blacklist?
&lt;/p&gt;
&lt;p&gt;
I wouldn't be too bothered except it's Ade's address and I think he probably wants access..
&lt;/p&gt;
&lt;p&gt;
Could you check the logs if there is a blacklist and remove 146.198.11.57
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/856#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/740</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/740</guid>
        <title>#740: Add 'class button block' to Soundcloud block</title>
        <pubDate>Thu, 12 Jun 2014 09:55:05 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Ben
&lt;/p&gt;
&lt;p&gt;
Could you add 'class button block' to the block class settings for this block:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/build/block/configure/block/98?destination=blogs%2Frob-hopkins"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/build/block/configure/block/98?destination=blogs%2Frob-hopkins&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Or shall I give myself 'developer' permissions so I can add these myself?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/740#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/735</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/735</guid>
        <title>#735: Add Annesley to github</title>
        <pubDate>Tue, 03 Jun 2014 11:05:40 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Once Annesley is on TRAC, we can point him at this ticket, he can give us his github id and we can add it &lt;a class="ext-link" href="https://github.com/orgs/transitionnetwork/members"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://github.com/orgs/transitionnetwork/members&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/735#changelog</comments>
    </item>
 </channel>
</rss>