<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket Query</title>
    <link>http://localhost:8080/trac/query?status=!closed&amp;billable=1&amp;order=status</link>
    <description>Support and issues tracking for the Transition Network Web Project.</description>
    <language>en-US</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/query?status=!closed&amp;billable=1&amp;order=status</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
        <link>http://localhost:8080/trac/ticket/645</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/645</guid>
        <title>#645: APC Tuning on Parrot and Penguin</title>
        <pubDate>Tue, 10 Dec 2013 10:52:31 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
As part of the upgrade from Squeeze to Wheezy, see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/535" title="maintenance: Upgrade Puffin, Penguin and Parrot from Debian Squeeze to Wheezy (closed: fixed)"&gt;ticket:535&lt;/a&gt;, Munin graphs for APC were added:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/parrot.transitionnetwork.org/index.html#php-apc"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/parrot.transitionnetwork.org/index.html#php-apc&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/penguin.transitionnetwork.org/index.html#php-apc"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/penguin.transitionnetwork.org/index.html#php-apc&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
There is also more APC info here:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://parrot.transitionnetwork.org/apc.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://parrot.transitionnetwork.org/apc.php&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/info/apc.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/info/apc.php&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
The documentation for the variables which can be set in &lt;tt&gt;/etc/php5/mods-available/apc.ini&lt;/tt&gt; can be found here:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://php.net/manual/en/apc.configuration.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://php.net/manual/en/apc.configuration.php&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
This monitoring is generating quite a high volume of warnings about fragmentation and purges and this ticket has been created to try to sort this issue out.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/645#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/655</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/655</guid>
        <title>#655: Add social media icons with counters to blogs listings views</title>
        <pubDate>Thu, 12 Dec 2013 13:03:11 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Investigate with Rob how to add Social media icons with counters into the /blogs listings views and individual node views.
&lt;/p&gt;
&lt;p&gt;
I suggest starting with just Rob's blogs (/rob-hopkins), separate context for 'Transition Culture section' and then roll it out over other blogs and maybe news content type once the /rob-hopkins has been trialled
&lt;/p&gt;
&lt;p&gt;
Sam to talk with Rob
&lt;/p&gt;
&lt;p&gt;
Also cc-ing Ben as design - theme guy
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/655#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/676</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/676</guid>
        <title>#676: Alternative to Skype for TTech Meetings</title>
        <pubDate>Tue, 14 Jan 2014 13:33:51 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Jim has pointed out that:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Skype costs us 15-30 minutes of grinding pain every time we do this!
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
So what are the alternatives and what are our requirements?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/676#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/814</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/814</guid>
        <title>#814: Higher that usual loads on PuffinServer since early September</title>
        <pubDate>Wed, 03 Dec 2014 17:12:35 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The following &lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/load.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;load graph&lt;/a&gt; from &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;PuffinServer&lt;/a&gt; shows that the load increased substantially in early September 2014, does anyone know why?
&lt;/p&gt;
&lt;p&gt;
&lt;a style="padding:0; border:none" href="http://localhost:8080/trac/attachment/ticket/814/puffin-load-2014-11-03.png"&gt;&lt;img src="http://localhost:8080/trac/raw-attachment/ticket/814/puffin-load-2014-11-03.png" /&gt;&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
When I found &lt;a class="ext-link" href="http://www.vdmi.nl/blog/i-went-drupal-733-and-all-i-got-was-slow-site"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;I went to Drupal 7.33 and all I got was a slow site&lt;/a&gt; I thought that perhaps a Drupal 7 site on the server could be the cause but 7.33 came out on &lt;a class="ext-link" href="https://www.drupal.org/drupal-7.33-release-notes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;7th November 2014&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Anyone have any ideas?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/814#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/881</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/881</guid>
        <title>#881: Site on ParrotServer with a memory leak?</title>
        <pubDate>Fri, 23 Oct 2015 11:19:04 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
It appears a site, or application, on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;ParrotServer&lt;/a&gt; might have a memory leak.
&lt;/p&gt;
&lt;p&gt;
&lt;a style="padding:0; border:none" href="http://localhost:8080/trac/attachment/ticket/881/parrot-memory-pinpoint-1411038915-1445598915.png"&gt;&lt;img src="http://localhost:8080/trac/raw-attachment/ticket/881/parrot-memory-pinpoint-1411038915-1445598915.png" /&gt;&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/881#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/898</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/898</guid>
        <title>#898: Fwd: Access to Drupal</title>
        <pubDate>Tue, 26 Jan 2016 17:35:05 GMT</pubDate>
        
        <dc:creator>ade</dc:creator>

        <description>&lt;pre class="wiki"&gt;Hi Chris,
The web team at the development agency are requesting access to the
webserver so that they can look at the sites make up.
(Please see below)
Would you please set up an account so that they can get root read access?
I guess this would be done via FTP, but your thoughts greatly appreciated.
best regards
Ade
---------- Forwarded message ----------
From: Ainslie Beattie &amp;lt;ainsliebeattie@transitionnetwork.org&amp;gt;
Date: 26 January 2016 at 17:25
Subject: Fwd: Access to Drupal
To: Sam Rossiter &amp;lt;samrossiter@transitionnetwork.org&amp;gt;, Ade Stuart &amp;lt;
adestuart@transitionnetwork.org&amp;gt;, Yvonne Struthers &amp;lt;yvonne@thisisyoke.com&amp;gt;
Hey both, can you please action this urgently so that Yoke can have access.
Cheers
---------- Forwarded message ----------
From: "Yvonne Struthers" &amp;lt;yvonne@thisisyoke.com&amp;gt;
Date: 26 Jan 2016 10:58
Subject: Access to Drupal
To: &amp;lt;ainsliebeattie@transitionnetwork.org&amp;gt;
Cc:
Hi Ainslie,
Just a quick email as I'm out seeing a client today,but just to say,it
looks like you have only given us access to the database. What we need
please is admin access to the Drupal site and to the code base so that we
can get a sense of how it's all set up.
Thanks in advance!
Yvonne
Sent from my iPhone
--
Ade Stuart
Web Manager - Transition network
07595 331877
The Transition Network is a registered charity
address: 43 Fore St, Totnes, Devon, TQ9 5HN, UK
website: www.transitionnetwork.org
TN company no: 6135675 TN charity no: 1128675
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/898#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/123</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/123</guid>
        <title>#123: City name in personal profiles</title>
        <pubDate>Tue, 20 Jul 2010 10:38:47 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Please either:
&lt;/p&gt;
&lt;ol class="loweralpha"&gt;&lt;li&gt;add city name into the personal profiles as it is in initiative profiles
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
OR:
&lt;/p&gt;
&lt;ol class="loweralpha" start="2"&gt;&lt;li&gt;if it's a straightforward replicate from the initiative profile, tell ed this and he will do it
&lt;/li&gt;&lt;/ol&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/123#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/127</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/127</guid>
        <title>#127: Link checker module</title>
        <pubDate>Fri, 23 Jul 2010 09:12:15 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
It would be very very handy to have a link checker of some form to check for internal and external links. Site editors are adding pages, navigation is changing etc. If possible, the link module would update links as they move internally, but that's a nice to have. Please install one and Ed can manage it.
&lt;/p&gt;
&lt;p&gt;
Putting to critical to get it on, shouldn't take long...
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/127#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/257</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/257</guid>
        <title>#257: Path aliases not being created for non-English nodes - i18n issues</title>
        <pubDate>Wed, 15 Jun 2011 13:24:21 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
WAS: "one resource not rendering URL"
&lt;/p&gt;
&lt;p&gt;
can't make this puppy render a human URL:
&lt;a class="ext-link" href="http://www.transitionnetwork.org/node/17135"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.transitionnetwork.org/node/17135&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
??
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/257#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/262</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/262</guid>
        <title>#262: US users adding Ini profiles through the US site</title>
        <pubDate>Fri, 17 Jun 2011 12:10:40 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
This is *the* big job for phase 4. The US is a pilot for other countries, and other content types. The aim is for TN to be able to publish project directory on TI sites, and enable anyone to add a project via the TI sites in the long term.
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;US user can add an ini profile to the US site which is also added to the TN directory
&lt;/li&gt;&lt;li&gt;US site has a special map and directory view of US inis only (both muller and official)
&lt;/li&gt;&lt;li&gt;US user can edit the ini profile via the US site (possibly not on TN site)
&lt;/li&gt;&lt;li&gt;US user account: with TN or TUS? tbd
&lt;/li&gt;&lt;li&gt;Creation of a 'slimline' user acct showing only 'critical data'?
&lt;/li&gt;&lt;li&gt;Creation of a 'slimline' ini profile showing only'critical data'?
&lt;/li&gt;&lt;li&gt;This is a pilot for other countries in the future
&lt;/li&gt;&lt;li&gt;This process will be used in some way to enable anyone to add project information from and through TI sites
&lt;/li&gt;&lt;li&gt;Fiddle with slimline user accounts and/or use third party process a la facebook/google/yahoo accts?
&lt;/li&gt;&lt;li&gt;US has a US-only map view of users who are speakers
&lt;/li&gt;&lt;/ol&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/262#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/264</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/264</guid>
        <title>#264: Context changes</title>
        <pubDate>Fri, 17 Jun 2011 12:23:53 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
As discussed at meeting. Contexts not really working. Blocks on a right all over the place. Perhaps need some new page layouts (?) or other piece of work with panels (?) to sort out.
&lt;/p&gt;
&lt;p&gt;
One page to start with is the Training page (and subsection). Ed to meet Trainers and their marketing consultant on 21/6.
&lt;/p&gt;
&lt;p&gt;
Jim please advise Ed what Jim needs to
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/264#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/320</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/320</guid>
        <title>#320: Add sitemap for site</title>
        <pubDate>Mon, 12 Sep 2011 09:26:57 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
...
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/320#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/326</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/326</guid>
        <title>#326: Usability changes as per the usability report</title>
        <pubDate>Mon, 12 Sep 2011 11:10:37 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Report has been circulated around ttech - to READ and then discuss - some will be phase 5 work, some will be the webmaster's responsibility...
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/326#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/457</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/457</guid>
        <title>#457: Projects form - Enhance form entry</title>
        <pubDate>Thu, 08 Nov 2012 18:15:44 GMT</pubDate>
        
        <dc:creator>laura</dc:creator>

        <description>&lt;p&gt;
1 - Entry Form:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Set up new fields and permissions and groupings
&lt;/li&gt;&lt;li&gt;Enhance ‘helper’ texts and any links to other parts of TN listed on form to enhance usability and context.
&lt;/li&gt;&lt;li&gt;CSS and potential of custom templating/panels if needed for style and layouts
&lt;/li&gt;&lt;/ul&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/457#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/461</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/461</guid>
        <title>#461: Spam account war</title>
        <pubDate>Wed, 21 Nov 2012 16:19:10 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Aim:
&lt;/p&gt;
&lt;p&gt;
tell drupal (and server level stuff?) to sniff out and destroy spam accounts without them knowing we did it, and ban them from doing it again
&lt;/p&gt;
&lt;p&gt;
Wiki page:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://wiki.transitionnetwork.org/Spam_accounts"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.transitionnetwork.org/Spam_accounts&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/461#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/469</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/469</guid>
        <title>#469: PSE project submission submitter cannot then edit their own project</title>
        <pubDate>Tue, 04 Dec 2012 19:33:46 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
The user who has added a pse submission which has been approved cannot then edit the project profile when it has been approved. The webmaster who approved it can edit it.
&lt;/p&gt;
&lt;p&gt;
This is not right - the user who added the pse submission which then got turned into a project needs to be the project owner.
&lt;/p&gt;
&lt;p&gt;
The new project is set to the correct author. But that author doesn't have edit rights.
&lt;/p&gt;
&lt;p&gt;
Project (unpublished):
&lt;a class="ext-link" href="https://www.transitionnetwork.org/projects/test-user-3-test-project"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/projects/test-user-3-test-project&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/469#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/488</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/488</guid>
        <title>#488: Set up Dev/Test and update CodeManagementReleaseProcess for new Aegir, Git, Drush make approach</title>
        <pubDate>Mon, 04 Feb 2013 19:07:31 GMT</pubDate>
        
        <dc:creator>jim</dc:creator>

        <description>&lt;p&gt;
This page is now out of date... &lt;a class="ext-link" href="https://tech.transitionnetwork.org/trac/wiki/CodeManagementReleaseProcess"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://tech.transitionnetwork.org/trac/wiki/CodeManagementReleaseProcess&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
This ticket is to update this with a new version, and set up Dev and Test environments, documenting all as we go.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/488#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/504</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/504</guid>
        <title>#504: Images missing from widget and site in general</title>
        <pubDate>Fri, 01 Mar 2013 16:00:39 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Submit button missing from widget (see bottom right here: &lt;a class="ext-link" href="http://www.edmitchell.co.uk/blog/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.edmitchell.co.uk/blog/&lt;/a&gt;).
&lt;/p&gt;
&lt;p&gt;
Quite a few images are missing from the site - profile pictures of people who don't have pictures as well.
&lt;/p&gt;
&lt;p&gt;
Please have a look.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/504#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/513</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/513</guid>
        <title>#513: Please clarify what is a widget user</title>
        <pubDate>Mon, 11 Mar 2013 08:17:47 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
What is a widget user? What role is this? Please clarify?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/513#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/514</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/514</guid>
        <title>#514: Spam issues - users not being able to comment</title>
        <pubDate>Tue, 12 Mar 2013 17:25:29 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Ed is receiving a selection of users not being allowed to post since the spam changes. We are seeing a pattern now. Setting this ticket up - will add user details tomorrow.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/514#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/516</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/516</guid>
        <title>#516: Search: not showing events or initiatives</title>
        <pubDate>Thu, 14 Mar 2013 10:16:41 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Search for Woking from homepage. I know that there are two events and two initaitives with Woking in them. Neither are shown:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/search/node/woking"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/search/node/woking&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Advanced search does not bring them up either (ticking the initiatives box).
&lt;/p&gt;
&lt;p&gt;
If I am in the initiatives section it returns the TIs though.
&lt;/p&gt;
&lt;p&gt;
General search used to show TIs and events. Now it's only showing results of word searches.
&lt;/p&gt;
&lt;p&gt;
General search needs to show TIs and events, and other nodes.
&lt;/p&gt;
&lt;p&gt;
Please look into this.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/516#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/517</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/517</guid>
        <title>#517: News widgets not working</title>
        <pubDate>Thu, 14 Mar 2013 12:39:57 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
News widgets not working - noticed here:
&lt;a class="ext-link" href="http://transitionfinsburypark.org.uk/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://transitionfinsburypark.org.uk/&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
and here:
&lt;a class="ext-link" href="http://wwww.edmitchell.co.uk"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wwww.edmitchell.co.uk&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Checked by putting code from &lt;a class="ext-link" href="http://www.transitionnetwork.org/syndication-and-social-media"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.transitionnetwork.org/syndication-and-social-media&lt;/a&gt; into new widget - showing a blank.
&lt;/p&gt;
&lt;p&gt;
News feed working here: &lt;a class="ext-link" href="http://www.transitionnetwork.org/news/feed"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.transitionnetwork.org/news/feed&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
So must be widget code.
&lt;/p&gt;
&lt;p&gt;
Adding to Jim, but is it Laura?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/517#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/541</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/541</guid>
        <title>#541: Documentation of the WordPress sites</title>
        <pubDate>Wed, 01 May 2013 20:25:57 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
These pages have been created for the documentation of the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;wiki:WordPress&lt;/a&gt; sites running on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer"&gt;wiki:PenguinServer&lt;/a&gt;:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/InTransitionWordPress"&gt;wiki:InTransitionWordPress&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/ReconomyWordPress"&gt;wiki:ReconomyWordPress&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/EarthInheritorsWordPress"&gt;wiki:EarthInheritorsWordPress&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
So far they only have a listing on the plugins for each site.
&lt;/p&gt;
&lt;p&gt;
Ideally they would document all the plugins, the theme and the steps that need to be taken to upgrade each site and also any other things that need documenting.
&lt;/p&gt;
&lt;p&gt;
Laura is this something you might be able to help with? I'm happy doing some work on it but you know your way around these sites far better than anyone else.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/541#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/582</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/582</guid>
        <title>#582: TN.org platform and sites</title>
        <pubDate>Mon, 02 Sep 2013 09:30:02 GMT</pubDate>
        
        <dc:creator>jim</dc:creator>

        <description>&lt;p&gt;
The TN.org platform and Drupal site updates are to be tracked in this ticket.
&lt;/p&gt;
&lt;p&gt;
Current PROD platform build = &lt;strong&gt;P009&lt;/strong&gt;
Current STG platform build = &lt;strong&gt;S010&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
Updates pending:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;SECURITY UPDATE - NO RISK: Pressflow core 6.30 is due, but the security holes fixed do not affect us, low priority. Platforms: present in S010, but not in P009.
&lt;/li&gt;&lt;/ul&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/582#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/587</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/587</guid>
        <title>#587: Puffin MySQL Tuning</title>
        <pubDate>Thu, 05 Sep 2013 12:54:47 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
This ticket is to track the tuning we do to MySQL on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;PuffinServer&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
See also previous comments on this issue:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:12" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:12&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:15" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:15&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:16" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:16&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:17" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:17&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:20" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:20&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:29" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:29&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#SettingsChanged" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#SettingsChanged&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:39" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:39&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:56" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:56&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:57" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:57&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:60" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:60&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:65" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:65&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:66" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:66&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:67" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:67&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:68" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:68&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:82" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:82&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555#comment:85" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555#comment:85&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/587#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/590</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/590</guid>
        <title>#590: Drupal performance improvements</title>
        <pubDate>Fri, 06 Sep 2013 10:27:27 GMT</pubDate>
        
        <dc:creator>jim</dc:creator>

        <description>&lt;p&gt;
This ticket is to track the work and changes done within the Drupal sphere in relation to performance enhancements done since &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/585" title="maintenance: TTech Meeting 5th September 2013 (closed: fixed)"&gt;#585&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
More information is needed and will come when &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/586" title="maintenance: New Relic Monitoring for BOA (closed: fixed)"&gt;ticket:586&lt;/a&gt; New Relic Monitoring for BOA is completed.
&lt;/p&gt;
&lt;p&gt;
I also note that many of these cleanup operations will also help make the move to D7 smoother and better.
&lt;/p&gt;
&lt;h1 id="Summaryofactionsandstatus"&gt;Summary of actions and status&lt;/h1&gt;
&lt;h2 id="TODO"&gt;TODO&lt;/h2&gt;
&lt;p&gt;
&lt;strong&gt;O) Stop making so many URL aliases for non-relevant pages, clean up url_alias table&lt;/strong&gt; -- 1/4-1/2 hour, medium reward, only risk is that some already broken links might break... Per chat with Ed, only these will be removed (plus releated tweaks to Pathauto settings):
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;3,579 entries where src = node/%/feed
&lt;/li&gt;&lt;li&gt;1,856 entries where src = user/%/contact
&lt;/li&gt;&lt;li&gt;= 5,435 or ~11% of entries in url_alias
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;strong&gt;L) Review slow query log, explain queries, tweak as necessary/flag poorly behaving modules.&lt;/strong&gt; 2-4 hours, high reward, low risk... Keep looking at the slow query log and adjust Drupal or find patches as necessary. ALSO related &lt;a class="ext-link" href="http://2bits.com/articles/reduce-your-servers-resource-usage-moving-mysql-temporary-directory-ram-disk.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Reduce your server's resource usage by moving MySQL temporary directory to tmpfs&lt;/a&gt;... Have opened ticket for this: &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/591" title="maintenance: Move MySQL temporary directory to tmpfs (closed: fixed)"&gt;#591&lt;/a&gt; for Chris.
&lt;/p&gt;
&lt;h3 id="Done"&gt;Done&lt;/h3&gt;
&lt;p&gt;
&lt;strong&gt;A) Remove spam taxonomy entries&lt;/strong&gt; &lt;del&gt;1/2 hour, Low risk, low reward -- See item 8 below. A simple delete from taxo term table where length &amp;gt; 50 is worth doing IMHO, and nothing I saw that would be clobbered is not spam.&lt;/del&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;B) Try a Taxonomy Cleanup&lt;/strong&gt;:  &lt;del&gt;3 hours, Medium risk, medium reward -- style module to try to merge terms with the same names and clean up the link tables back to nodes. Further, we can remove any taxonomies or relations to certain CTs that don't really add value.&lt;/del&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;D) Review Views caching&lt;/strong&gt; &lt;del&gt;1 hour, low risk, high reward -- Utilise Views Content Cache this was done a while back but I think -- done (task 12) in comment 21.&lt;/del&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;F) Force blocks caches to cached appropriately (and be rendered/included only as needed)&lt;/strong&gt; &lt;del&gt;1-2 hours, medium reward, low risk -- BOA packages the &lt;a class="ext-link" href="https://drupal.org/project/blockcache_alter"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Block Cache Alter&lt;/a&gt;, which makes sure Drupal only renders blocks when needed. Potential small but nice boost quickly in whole site. -- per comment 22, block caching is disabled by other modules so this will have to go on hold for now.&lt;/del&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;H) Remove &lt;a class="missing wiki"&gt;CustomError?&lt;/a&gt; module all together&lt;/strong&gt; &lt;del&gt;1/2 hour, low risk, low reward -- We should take out the PHP code from the 403 section of &lt;a class="missing wiki"&gt;CustomError?&lt;/a&gt; and put it into a simple page entry. See comment 6 below as this has happened for 404s (which need no PHP). We can then remove the &lt;a class="missing wiki"&gt;CustomError?&lt;/a&gt; module all together, saving lots of sessions. I would go ahead and do this but since the 403 page has various displays depending on user type, I wanted to raise it here as it *may* have side effects. Or not...&lt;/del&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;I) Re-enable block caching.&lt;/strong&gt; &lt;del&gt;2-6 hours, high risk, high reward -- Per comment 24, a module (probably Content Access) is stopping Drupal caching blocks, which for some of them means a fair amount of pointless overhead. We need to somehow get around this and get blocks cached if possible. R&amp;amp;D mainly, perhaps with some hacking/patching - but I'd stop short of doing this if so.&lt;/del&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;K) Add &amp;amp; enable Views Lite Pager on big views.&lt;/strong&gt; &lt;del&gt;1 hour, low risk, low reward -- Using this module stops a heavy count query on views with pagers -- recommended for large sites.&lt;/del&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;M) Take control of Cron, and maximise time pages are cached for.&lt;/strong&gt; &lt;del&gt;.25h, high reward, low risk -- Cron is wiping the page cache, so we need to install &lt;a class="ext-link" href="https://drupal.org/project/elysia_cron"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/project/elysia_cron&lt;/a&gt; so we can clear the page less often, and run other things when we want and the site is quieter. Now need per minute resolution set to get the best, see comment 33 and 34 for more...&lt;/del&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;N) Replace Admin Menu 1.x with 3.x&lt;/strong&gt; -- will happen when &lt;a class="assigned ticket" href="http://localhost:8080/trac/ticket/590" title="defect: Drupal performance improvements (assigned)"&gt;#590&lt;/a&gt; occurs, marking complete here -- &lt;del&gt;5 mins, high reward, low risk -- done when &lt;a class="assigned ticket" href="http://localhost:8080/trac/ticket/582" title="maintenance: TN.org platform and sites (assigned)"&gt;#582&lt;/a&gt; happens, could be the cause of some load spikes as it occasionally goes made and does 2000-5000 queries~~
&lt;/del&gt;&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/590#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/596</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/596</guid>
        <title>#596: Captions issue</title>
        <pubDate>Mon, 16 Sep 2013 16:58:04 GMT</pubDate>
        
        <dc:creator>benj</dc:creator>

        <description>&lt;p&gt;
basically captions are appearing on body inline images and featured images on STG but not PROD and I can't see where the difference is...
&lt;/p&gt;
&lt;p&gt;
The following code addition to the bottom of template.php should be (but isn't) adding the caption class to images such as the one at the top of this page:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/blogs/ed-mitchell/2013-06/test-blog-test-caption-and-featured-image"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/blogs/ed-mitchell/2013-06/test-blog-test-caption-and-featured-image&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Any reason you can think of why not? Or do you know of another easy way of adding the class caption to featured image fields? (I guess the module &lt;a class="ext-link" href="https://drupal.org/project/semantic_cck"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/project/semantic_cck&lt;/a&gt; - but maybe overkill...)
&lt;/p&gt;
&lt;p&gt;
/&lt;strong&gt;
&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Adds caption css class to featured images
*/
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
function transition2_imagecache_formatter_featured_image_default($element) {
&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;em&gt; Inside a view $element may contain NULL data. In that case, just return.
if (empty($element&lt;a class="wiki" href="http://localhost:8080/trac/wiki/WikiStart#item"&gt;#item&lt;/a&gt;&lt;a class="missing wiki"&gt;fid?&lt;/a&gt;)) {
&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
return &lt;em&gt;;
&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
}
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;em&gt; Extract the preset name from the formatter name.
$presetname = substr($element&lt;a class="wiki" href="http://localhost:8080/trac/wiki/WikiStart#formatter"&gt;#formatter&lt;/a&gt;, 0, strrpos($element&lt;a class="wiki" href="http://localhost:8080/trac/wiki/WikiStart#formatter"&gt;#formatter&lt;/a&gt;, '_'));
$style = 'linked';
$style = 'default';
&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;
$item = $element&lt;a class="wiki" href="http://localhost:8080/trac/wiki/WikiStart#item"&gt;#item&lt;/a&gt;;
$item&lt;a class="missing wiki"&gt;data?&lt;/a&gt;&lt;a class="missing wiki"&gt;alt?&lt;/a&gt; = isset($item&lt;a class="missing wiki"&gt;data?&lt;/a&gt;&lt;a class="missing wiki"&gt;alt?&lt;/a&gt;) ? $item&lt;a class="missing wiki"&gt;data?&lt;/a&gt;&lt;a class="missing wiki"&gt;alt?&lt;/a&gt; : &lt;em&gt;;
$item&lt;a class="missing wiki"&gt;data?&lt;/a&gt;&lt;a class="missing wiki"&gt;title?&lt;/a&gt; = isset($item&lt;a class="missing wiki"&gt;data?&lt;/a&gt;&lt;a class="missing wiki"&gt;title?&lt;/a&gt;) ? $item&lt;a class="missing wiki"&gt;data?&lt;/a&gt;&lt;a class="missing wiki"&gt;title?&lt;/a&gt; : NULL;
&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;
$class = "imagecache imagecache-$presetname imagecache-$style imagecache-{$element&lt;a class="wiki" href="http://localhost:8080/trac/wiki/WikiStart#formatter"&gt;#formatter&lt;/a&gt;} caption";
return theme('imagecache', $presetname, $item&lt;a class="missing wiki"&gt;filepath?&lt;/a&gt;, $item&lt;a class="missing wiki"&gt;data?&lt;/a&gt;&lt;a class="missing wiki"&gt;alt?&lt;/a&gt;, $item&lt;a class="missing wiki"&gt;data?&lt;/a&gt;&lt;a class="missing wiki"&gt;title?&lt;/a&gt;, array('class' =&amp;gt; $class));
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
}
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/596#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/636</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/636</guid>
        <title>#636: Changes to Space.transitionnetwork.org homepage to facilitate user registration</title>
        <pubDate>Wed, 27 Nov 2013 17:30:19 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Space currently does not give users who aren't already registered a way in. Anon users can see some of the spaces but when they try to apply for membership, they hit a login page, which they can't complete as they are not registered.
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;RTFM for OA as to OA best practice - this is billable time. Then leave notes about it in wiki for later developers.
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="2"&gt;&lt;li&gt;The homepage needs editing to sort this out. Here are some first changes:
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
2.1. Remove the 'Need the pros' pane (RHS)
2.2 Remove the 'Just getting started' pane (LHS)
2.3 Add a 'Request membership' pane which is basically a user registration form. Make registration 'approval only' for now, approval to be by a site admin (webproject@…)
&lt;/p&gt;
&lt;p&gt;
The /spaces listings view shows the spaces that are publicly viewable, and there is a 'request group membership' button for each of them.
&lt;/p&gt;
&lt;ol start="3"&gt;&lt;li&gt;Can you make this into a registration form as well?
&lt;/li&gt;&lt;/ol&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/636#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/638</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/638</guid>
        <title>#638: Question about notifications option for content creators</title>
        <pubDate>Thu, 28 Nov 2013 12:32:57 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Content creators (news, Rob's blog, social reporters) struggle with the notifications. the problem is that they forget to click the option to 'do not send notifications for this update' and then notifications are sent out. It is easy for us to think this is easy for them, but when you are bashing stuff out in a hurry, it's easy to forget this fiddly bit.
&lt;/p&gt;
&lt;p&gt;
CAN WE set drupal to NOT send notifications out as standard for some of the content types?
&lt;/p&gt;
&lt;p&gt;
And change it so that the content creators (news, Rob's blog, social reporters) choose to SEND notifications out instead (of NOT sending them)
?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/638#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/662</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/662</guid>
        <title>#662: Subscriptions' links in text emails breaking</title>
        <pubDate>Tue, 17 Dec 2013 15:37:13 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
for January - to get Sam and Jim talking - in January
&lt;/p&gt;
&lt;p&gt;
The subs sent out to subscribers: are fine in html but the text version is broken and unsatisfactory. I know we've been through this and it's a known bug etc. etc. but I'm wondering if we can switch all subs to html, or if there are any patches to this problem?
&lt;/p&gt;
&lt;p&gt;
Adding as Jim's ticket with Sam cc-ed
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/662#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/701</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/701</guid>
        <title>#701: Emails &amp; Telephone calls</title>
        <pubDate>Tue, 18 Mar 2014 09:38:24 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description></description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/701#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/711</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/711</guid>
        <title>#711: Emails &amp; Telephone calls</title>
        <pubDate>Tue, 01 Apr 2014 13:47:56 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description></description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/711#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/714</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/714</guid>
        <title>#714: Drop down menu useability on devices with touch screens</title>
        <pubDate>Sat, 05 Apr 2014 09:21:46 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The main menu bar across the top of the Transition Network site has a drop down navigation menu which appears to only be usable with Firefox on Android if a mouse is attached -- without a mouse it's not possible to select items from the drop down menu. I would guess that this is because something like onMouseOver isn't available in situations like this?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/714#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/727</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/727</guid>
        <title>#727: Change background on block from orange to white</title>
        <pubDate>Fri, 16 May 2014 10:02:17 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Ben
&lt;/p&gt;
&lt;p&gt;
Rob wants a list of the themes presented in a block.
&lt;/p&gt;
&lt;p&gt;
I did the block: &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/build/block/configure/block/97"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/build/block/configure/block/97&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
But it appears with an orange background. The block is visible towards the bottom of the page (for logged in admins) here: &lt;a class="ext-link" href="https://www.transitionnetwork.org/blogs/rob-hopkins"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/blogs/rob-hopkins&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
If I put the block on other pages it appears with a white background.
&lt;/p&gt;
&lt;p&gt;
I tried to hack it with some inline CSS but failed.
&lt;/p&gt;
&lt;p&gt;
Could you take a look?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/727#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/737</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/737</guid>
        <title>#737: SPF / Emails rejected from the website contact form</title>
        <pubDate>Thu, 05 Jun 2014 15:46:13 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
We had a user report that they could not send a message via our contact form:
&lt;/p&gt;
&lt;p&gt;
"Yesterday I sent a message to you via the contact form on the website. But obviously something went wrong: for I got a failure notice saying my message could not be delivered. Therefore I'm sending it directly via email (see below) hoping that you're receiving my message this way."
&lt;/p&gt;
&lt;p&gt;
&amp;lt;info@…&amp;gt;: host mx1.spamfiltering.com[72.249.150.158] said:
&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
550 81.95.XX.XX is not allowed to send mail from gmx.de. Please see
&lt;a class="ext-link" href="http://www.openspf.net/Why?scope=mfrom;identity=userXX@gmx.de;ip=81.95.XX.XX"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.openspf.net/Why?scope=mfrom;identity=userXX@gmx.de;ip=81.95.XX.XX&lt;/a&gt;
(in reply to end of DATA command)
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
(User details edited as this is publicly archived)
&lt;/p&gt;
&lt;p&gt;
I'm not sure I quite understand what's going on here. Chris indicated in email that this would affect other users whose email provider has set this kind of SPF record.
&lt;/p&gt;
&lt;p&gt;
Can we make an educated guess as to what proportion of email providers set this kind of SPF?
&lt;/p&gt;
&lt;p&gt;
How many messages do we never get to see? Is it a problem? Or a small enough number of users that we just don't worry about it?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/737#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/758</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/758</guid>
        <title>#758: * Advisory ID: DRUPAL-SA-CORE-2014-003</title>
        <pubDate>Wed, 16 Jul 2014 21:55:29 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description>&lt;p&gt;
View online: &lt;a class="ext-link" href="https://www.drupal.org/SA-CORE-2014-003"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/SA-CORE-2014-003&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Advisory ID: DRUPAL-SA-CORE-2014-003
&lt;/li&gt;&lt;li&gt;Project: Drupal core &lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Version: 6.x, 7.x
&lt;/li&gt;&lt;li&gt;Date: 2014-July-16
&lt;/li&gt;&lt;li&gt;Security risk: Critical &lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Exploitable from: Remote
&lt;/li&gt;&lt;li&gt;Vulnerability: Multiple vulnerabilities
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
Multiple vulnerabilities were fixed in the supported Drupal core versions 6
and 7.
&lt;/p&gt;
&lt;p&gt;
.... Denial of service with malicious HTTP Host header (Base system - Drupal
6 and 7 - Critical)
&lt;/p&gt;
&lt;p&gt;
Drupal core's multisite feature dynamically determines which configuration
file to use based on the HTTP Host header.
&lt;/p&gt;
&lt;p&gt;
The HTTP Host header validation does not sufficiently check
maliciously-crafted header values, thereby exposing a denial of service
vulnerability.
&lt;/p&gt;
&lt;p&gt;
.... Access bypass (File module - Drupal 7 - Critical)
&lt;/p&gt;
&lt;p&gt;
The File module included in Drupal 7 core allows attaching files to pieces of
content. The module doesn't sufficiently check permission to view the
attached file when attaching a file that was previously uploaded. This could
allow attackers to gain access to private files.
&lt;/p&gt;
&lt;p&gt;
This vulnerability is mitigated by the fact that the attacker must have
permission to create or edit content with a file field.
&lt;/p&gt;
&lt;p&gt;
Note: The Drupal 6 &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; module is affected by a similar issue (see
SA-CONTRIB-2014-071 - &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; - Access bypass &lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt;) and requires an update
to the current security release of Drupal 6 core in order for the fix
released there to work correctly. However, Drupal 6 core itself is not
directly affected.
&lt;/p&gt;
&lt;p&gt;
.... Cross-site scripting (Form API option groups - Drupal 6 and 7 -
Moderately critical)
&lt;/p&gt;
&lt;p&gt;
A cross-site scripting vulnerability was found due to Drupal's form API
failing to sanitize option group labels in select elements. This
vulnerability affects Drupal 6 core directly, and likely affects Drupal 7
forms provided by contributed or custom modules.
&lt;/p&gt;
&lt;p&gt;
This vulnerability is mitigated by the fact that it requires the "administer
taxonomy" permission to exploit in Drupal 6 core, and there is no known
exploit within Drupal 7 core itself.
&lt;/p&gt;
&lt;p&gt;
.... Cross-site scripting (Ajax system - Drupal 7 - Moderately critical)
&lt;/p&gt;
&lt;p&gt;
A reflected cross-site scripting vulnerability was found in certain forms
containing a combination of an Ajax-enabled textfield (for example, an
autocomplete field) and a file field.
&lt;/p&gt;
&lt;p&gt;
This vulnerability is mitigated by the fact that an attacker can only trigger
the attack in a limited set of circumstances, usually requiring custom or
contributed modules.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;/A CVE identifier &lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt; will be requested, and added upon issuance, in
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
accordance with Drupal Security Team processes./
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Drupal core 6.x versions prior to 6.32.
&lt;/li&gt;&lt;li&gt;Drupal core 7.x versions prior to 7.29.
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
Install the latest version:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;If you use Drupal 6.x, upgrade to Drupal core 6.32. &lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;If you use Drupal 7.x, upgrade to Drupal core 7.29. &lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Also see the Drupal core &lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt; project page.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;The denial of service vulnerability using malicious HTTP Host headers was
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
reported by Régis Leroy &lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt;.
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;The access bypass vulnerability in the File module was reported by Ivan
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Ch
&lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt;.
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;The cross-site scripting vulnerability with Form API option groups was
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
reported by Károly Négyesi &lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt;.
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;The cross-site scripting vulnerability in the Ajax system was reported by
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
mani22test &lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt;.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;The denial of service vulnerability using malicious HTTP Host headers was
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
fixed by Régis Leroy &lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt;, and by Klaus Purer &lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt; of the Drupal
Security
Team.
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;The access bypass vulnerability in the File module was fixed by Nate Haug
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt; and Ivan Ch &lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt;, and by Drupal Security Team members David
Rothstein
&lt;a class="missing changeset" title="No default repository defined"&gt;[17]&lt;/a&gt;, Heine Deelstra &lt;a class="missing changeset" title="No default repository defined"&gt;[18]&lt;/a&gt; and David Snopek &lt;a class="missing changeset" title="No default repository defined"&gt;[19]&lt;/a&gt;.
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;The cross-site scripting vulnerability with Form API option groups was
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
fixed by Greg Knaddison &lt;a class="missing changeset" title="No default repository defined"&gt;[20]&lt;/a&gt; of the Drupal Security Team.
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;The cross-site scripting vulnerability in the Ajax system was fixed by
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Neil Drumm &lt;a class="missing changeset" title="No default repository defined"&gt;[21]&lt;/a&gt; of the Drupal Security Team.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;The Drupal Security Team &lt;a class="missing changeset" title="No default repository defined"&gt;[22]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
The Drupal security team can be reached at security at drupal.org or via the
contact form at &lt;a class="ext-link" href="http://drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/contact&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[23]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Learn more about the Drupal Security team and their policies &lt;a class="missing changeset" title="No default repository defined"&gt;[24]&lt;/a&gt;, writing
secure code for Drupal &lt;a class="missing changeset" title="No default repository defined"&gt;[25]&lt;/a&gt;, and securing your site &lt;a class="missing changeset" title="No default repository defined"&gt;[26]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Follow the Drupal Security Team on Twitter at
&lt;a class="ext-link" href="https://twitter.com/drupalsecurity"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://twitter.com/drupalsecurity&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[27]&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/project/drupal"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/project/drupal&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team/risk-levels"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team/risk-levels&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/project/filefield"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/filefield&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/node/2304561"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/node/2304561&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt; &lt;a class="ext-link" href="http://cve.mitre.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://cve.mitre.org/&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/drupal-6.32-release-notes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/drupal-6.32-release-notes&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/drupal-7.29-release-notes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/drupal-7.29-release-notes&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/project/drupal"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/project/drupal&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/1367862"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/1367862&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/556138"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/556138&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/chx"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/chx&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/2844779"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/2844779&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/1367862"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/1367862&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/262198"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/262198&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/35821"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/35821&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/556138"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/556138&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[17]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/124982"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/124982&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[18]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/17943"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/17943&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[19]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/266527"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/266527&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[20]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/greggles"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/greggles&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[21]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/drumm"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/drumm&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[22]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[23]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/contact&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[24]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[25]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/writing-secure-code"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/writing-secure-code&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[26]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security/secure-configuration"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security/secure-configuration&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[27]&lt;/a&gt; &lt;a class="ext-link" href="https://twitter.com/drupalsecurity"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://twitter.com/drupalsecurity&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;_
Security-news mailing list
Security-news@…
Unsubscribe at &lt;a class="ext-link" href="https://lists.drupal.org/mailman/listinfo/security-news"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://lists.drupal.org/mailman/listinfo/security-news&lt;/a&gt;
&lt;/span&gt;&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/758#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/772</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/772</guid>
        <title>#772: new TIs not appearing on staging until caches flushed</title>
        <pubDate>Tue, 05 Aug 2014 09:26:32 GMT</pubDate>
        
        <dc:creator>annesley</dc:creator>

        <description>&lt;p&gt;
i added a new Mulling transition initiative on staging in Afghanistan and it did not appear on the map... i flushed caches and then it started appearing on the main initiatives map. is this intended? is it a known?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/772#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/304</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/304</guid>
        <title>#304: Make the five star ratings filter-able in the resources directory view</title>
        <pubDate>Thu, 18 Aug 2011 16:55:00 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description></description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/304#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/384</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/384</guid>
        <title>#384: Enhance Project Profile Content Type and directory</title>
        <pubDate>Tue, 20 Dec 2011 23:25:32 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Laura to re-design IA and interface for admin and public profiles for project profile CT and directory.
&lt;/p&gt;
&lt;p&gt;
Considered as part of PSE Project, hence design in Jan, build in Feb 2012
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/384#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/458</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/458</guid>
        <title>#458: Projects form - Project profile page display</title>
        <pubDate>Thu, 08 Nov 2012 18:17:09 GMT</pubDate>
        
        <dc:creator>laura</dc:creator>

        <description>&lt;p&gt;
2 – Project Profile individual page display
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Panels to re-arrange layout.
&lt;/li&gt;&lt;li&gt;Summary on left upper brick, findability on right upper brick with map under (will be a case of working on mockups via LW’s virtual machine, map may need to go further down, but a listing of town, country still to appear in top part). Description to become an expanding box and other data underneath - full width.
&lt;/li&gt;&lt;li&gt;Tidy up image display to be more attractive for users. Enable ‘contact’ button for project contact to be more visible.
&lt;/li&gt;&lt;li&gt;Panels, views, and CSS theming for frontend enhanced display.
&lt;/li&gt;&lt;/ul&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/458#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/459</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/459</guid>
        <title>#459: Projects form - Project Directory display</title>
        <pubDate>Thu, 08 Nov 2012 18:19:53 GMT</pubDate>
        
        <dc:creator>laura</dc:creator>

        <description>&lt;p&gt;
&lt;strong&gt;3 - Projects Directory (frontend of website)&lt;/strong&gt;
Create new tabbed views for a variety of outputs. New views result listings to be mainly in display format of:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Title (heading)
&lt;/li&gt;&lt;li&gt;&lt;a class="missing wiki"&gt;City/Country?&lt;/a&gt; (bold, slightly larger and possible on right)
&lt;/li&gt;&lt;li&gt;New summary field and ‘read more about this project’ link
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;em&gt;Similar to the ‘full’ PSE widget output list (except not showing distance but town or city and Country)&lt;/em&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Tabs:&lt;/strong&gt;
&lt;strong&gt;Tab One&lt;/strong&gt; (default)
Projects Home –
Introduction short paragraph text and link to adding projects.
Lists featured projects
Pagination
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Tab Two&lt;/strong&gt;
Find by theme –
Introduction brief sentence.
Search functionality (exposed view filter) for selection of projects by theme.
Default view: random
pagination
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Tab Three&lt;/strong&gt;
Find by location -
Introduction brief sentence.
Search functionality (exposed view filter) for selection of projects by location to use Names rather than miles.
Default view: random or London? &lt;em&gt;(note: LW will test ideas on this)&lt;/em&gt;
pagination
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Tab Four&lt;/strong&gt;
Find by benefits –
&lt;em&gt;&lt;strong&gt; note this may need to be set up ready but hidden initially until a substantial number of projects have updated their profiles with inclusion of the benefits/outcomes field &lt;/strong&gt;&lt;/em&gt;
Introduction brief sentence.
Search functionality (exposed view filter) for selection of projects by outcome/benefits
Default view: all by date added.
pagination
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Tab five&lt;/strong&gt;
[Similar to existing projects home page]
Find by title with exposed search as is present.
and tabular layout with a-z
Custom CSS may be needed
&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;
&lt;strong&gt;Longer term:&lt;/strong&gt; (possible January?)
Enhance projects map page to show attached view of latest projects with relational popups on hover for easy browsing, and / or map filters by theme or benefit to enable a more usable feature of the map ability.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/459#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/485</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/485</guid>
        <title>#485: transitionnetwork.org is tablet/phone/touch unfriendly</title>
        <pubDate>Tue, 29 Jan 2013 09:24:15 GMT</pubDate>
        
        <dc:creator>mark</dc:creator>

        <description>&lt;p&gt;
Don't know how much of a priority this is, but transitionnetwork.org seems tablet/phone/touch unfriendly - and I'm just raising this ticket to capture this thought.
&lt;/p&gt;
&lt;p&gt;
Core issue is the drop-down menus that are only accessible if you can "hover" over them with a mouse pointer - and of course no such thing exists on a touch-screen phone or tablet.
&lt;/p&gt;
&lt;p&gt;
An easy workaround would be sub-menus or section menus in the sidebar, though I guess that would need some thought so as not to over-clutter the user interface.  I often use the menu_block module to make "section" menus easy.
&lt;/p&gt;
&lt;p&gt;
Anyway - thought captured - back to Real Work now :)
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/485#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/519</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/519</guid>
        <title>#519: Fixing various URL in the Database</title>
        <pubDate>Fri, 15 Mar 2013 13:47:21 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
This page:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://transitionnetwork.org/support/what-transition-initiative"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://transitionnetwork.org/support/what-transition-initiative&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Contains this HTML:
&lt;/p&gt;
&lt;pre class="wiki"&gt;&amp;lt;p&amp;gt;&amp;lt;img alt="TransitionSantaCruz" src="http://transitionsc.org/sites/www.transitionnetwork.org/files/pixture_reloaded_logo.png" align="right" height="69" width="150"&amp;gt;&amp;lt;/p&amp;gt;
&lt;/pre&gt;&lt;p&gt;
The image is a 404:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://transitionsc.org/sites/www.transitionnetwork.org/files/pixture_reloaded_logo.png"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://transitionsc.org/sites/www.transitionnetwork.org/files/pixture_reloaded_logo.png&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
The correct location for the image is:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://transitionsc.org/sites/default/files/pixture_reloaded_logo.png"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://transitionsc.org/sites/default/files/pixture_reloaded_logo.png&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Looking at the Internet Archive this was correct back in October 2012,
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://web.archive.org/web/20121022030350/http://www.transitionnetwork.org/support/what-transition-initiative"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://web.archive.org/web/20121022030350/http://www.transitionnetwork.org/support/what-transition-initiative&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Their munged HTML contains the correct URL:
&lt;/p&gt;
&lt;pre class="wiki"&gt;&amp;lt;p&amp;gt;&amp;lt;a href="/web/20121022030350/http://transitionsc.org/sites/default/files/pixture_reloaded_logo.png" class="colorbox initColorbox-processed cboxElement"&amp;gt;
&lt;/pre&gt;&lt;p&gt;
It appears to me that an edit must have been done on the database something like:
&lt;/p&gt;
&lt;pre class="wiki"&gt;s;/sites/default/files/;/sites/www.transitionnetwork.org/files/;
&lt;/pre&gt;&lt;p&gt;
There might well be other URLs to other Drupal sites that were changed when they shouldn't have been?
&lt;/p&gt;
&lt;p&gt;
I have had a quick look at the database dump and couldn't find any examples of this problem, but there are 113 lines to check:
&lt;/p&gt;
&lt;pre class="wiki"&gt;grep "sites/www.transitionnetwork.org/files" /var/backups/mysql/sqldump/transitionnetwor.sql | wc -l
113
&lt;/pre&gt;&lt;p&gt;
I did notice that there are a lot of URLs in the database like this:
&lt;/p&gt;
&lt;pre class="wiki"&gt;src=\"http://www.transitionnetwork.org/sites/www.transitionnetwork.org/files/uploaded/u5857/Map-TransitionNetworkOffice.jpg\"
&lt;/pre&gt;&lt;p&gt;
And
&lt;/p&gt;
&lt;pre class="wiki"&gt;src=\"https://www.transitionnetwork.org/sites/www.transitionnetwork.org/files/uploaded/u4/transition%20companion%20cover.jpg\"
&lt;/pre&gt;&lt;p&gt;
Both the above links would be better starting with &lt;tt&gt;/&lt;/tt&gt; or &lt;tt&gt;//www.transitionnetwork.org/&lt;/tt&gt; as this would avoid people getting HTTPS content when using HTTP and also getting HTTP content when using HTTPS.
&lt;/p&gt;
&lt;p&gt;
I think it would be worth putting the site into maintenance mode, doing a dump of the database, checking these 113 lines for issues like those above, correcting them all and then reinserting the data, however this would need to be done at a suitable time.
&lt;/p&gt;
&lt;p&gt;
I'd be happy to do this task. Ed, Jim, any thoughts about when would be a good time to do it?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/519#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/520</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/520</guid>
        <title>#520: Session 443 config in settings.php</title>
        <pubDate>Fri, 15 Mar 2013 23:16:49 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
There is this warning displaying at &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/reports/status"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/reports/status&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;Settings.php is not setup correctly. With the current configuration of 443 Session module, the following lines must be in settings.php.
      if (!empty($_SERVER['HTTPS']) &amp;amp;&amp;amp; $_SERVER['HTTPS'] != 'off') {
        ini_set('session.cookie_secure', 1);
      }
&lt;/pre&gt;&lt;p&gt;
Based on the check of what is happening with cookies done on &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/371#comment:34" title="maintenance: Piwik Hosting (closed: fixed)"&gt;ticket:371#comment:34&lt;/a&gt; and &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/371#comment:36" title="maintenance: Piwik Hosting (closed: fixed)"&gt;ticket:371#comment:36&lt;/a&gt; things are currently working OK, session cookies do have the secure flag set, so I'm a bit confused by this warning message. I also think that the PHP suggested to add to settings.php looks perfectly sensible and should be included, I'm sure we did have it on the old server, however there are 33 settings.php files on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt; and I'm not clear which one the live site uses.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/520#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/521</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/521</guid>
        <title>#521: MySQL Unsafe statement warnings in the daemon.log</title>
        <pubDate>Sat, 16 Mar 2013 09:46:57 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
I don't know if these matter?
&lt;/p&gt;
&lt;p&gt;
I found them when hunting for 502 errors.
&lt;/p&gt;
&lt;pre class="wiki"&gt;grep "Unsafe statement written to the binary log" /var/log/daemon.log | wc -l
343
&lt;/pre&gt;&lt;p&gt;
Some examples:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Mar 16 09:28:20 puffin mysqld: 130316  9:28:20 [Warning] Unsafe statement written to the binary log using statement format since BINLOG_FORMAT = STATEMENT. Statements writing to a table with an auto-increment column after selecting from another table are unsafe because the order in which rows are retrieved determines what (if any) rows will be written. This order cannot be predicted and may differ on master and the slave. Statement: DELETE FROM notifications_event WHERE created &amp;lt; 1363426040 AND eid &amp;lt; (SELECT MIN(eid) FROM notifications_queue)
&lt;/pre&gt;&lt;pre class="wiki"&gt;Mar 16 05:52:12 puffin mysqld: 130316  5:52:12 [Warning] Unsafe statement written to the binary log using statement format since BINLOG_FORMAT = STATEMENT. Statements writing to a table with an auto-increment column after selecting from another table are unsafe because the order in which rows are retrieved determines what (if any) rows will be written. This order cannot be predicted and may differ on master and the slave. Statement: INSERT INTO notifications_queue (uid, mdid, send_method, sid, module, eid, send_interval, language, cron, created, conditions) SELECT DISTINCT s.uid, s.mdid, s.send_method, s.sid, s.module, 61233, s.send_interval, s.language, s.cron, 1363413132, s.conditions FROM notifications s LEFT JOIN notifications_fields f ON s.sid = f.sid WHERE (s.status = 1) AND (s.event_type = 'node') AND (s.send_interval &amp;gt;= 0) AND ((f.field = 'nid' AND f.intval = 30718) OR (f.field = 'type' AND f.value = 'profile') OR (f.field = 'author' AND f.intval = 16908)) GROUP BY s.uid, s.mdid, s.send_method, s.sid, s.module, s.send_interval, s.
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/521#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/523</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/523</guid>
        <title>#523: Database intergrity</title>
        <pubDate>Tue, 19 Mar 2013 11:33:38 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Following on from comment 4 of ticket 516 (&lt;a class="ext-link" href="https://tech.transitionnetwork.org/trac/ticket/516#comment:4"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://tech.transitionnetwork.org/trac/ticket/516#comment:4&lt;/a&gt;) , I wanted to check the integrity of the field tables, so I crafted and ran this query:
&lt;/p&gt;
&lt;p&gt;
SELECT count(cck.nid) FROM &lt;tt&gt;content_field_region&lt;/tt&gt; cck
LEFT JOIN node node on cck.nid = node.nid
WHERE node.nid IS NULL
&lt;/p&gt;
&lt;p&gt;
Which returned 1,173 rows. I then replaced the 'content_field_region' with other fields found on the user profile nodes (which have their own database table) so the full breakdown is:
&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
content_field_region = 1173
content_field_initiative = 1165
content_field_themes = 6256
content_field_training_attended = 1165
content_field_roles_offered = 1285
content_field_other_websites = 1181
content_field_user_types = 1165
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
So what this means is there are around 1200 entries in field database storage for the above tables that do not have an associated node. This means the data is not properly referentially integral, and ideally these should be cleaned up one day.
&lt;/p&gt;
&lt;p&gt;
The risk is low but it's worth doing a the rest of the audit (with the other fields that have tables of their own) and then cleaning these up at some point. These will have been caused by manual deletes and imports over the years. Drupal would normally keep these sorted but we've had to bypass Drupal a few times.
&lt;/p&gt;
&lt;p&gt;
Or we can leave it as is and let the migration to Drupal 8 resolve this. The cost is a bit more database space and a slightly slower site... Though this *may* cause a bug or two.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/523#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/533</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/533</guid>
        <title>#533: Five star ratings: remove from resources CT</title>
        <pubDate>Mon, 22 Apr 2013 10:56:34 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
We aren't using the fivestar ratings from the resources CT. There were some problems with it ages ago. Remove them from the resources CT and interface (public and edit)
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/533#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/537</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/537</guid>
        <title>#537: Parrot setup and documentation</title>
        <pubDate>Tue, 30 Apr 2013 11:11:36 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Things done setting up parrot.webarch.net -- a new virtual machine for running Wordpress sites, see &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;wiki:ParrotServer&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/537#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/540</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/540</guid>
        <title>#540: HTTPS for WordPress sites</title>
        <pubDate>Wed, 01 May 2013 20:20:32 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Currently the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;wiki:WordPress&lt;/a&gt; sites have have the following SSL certificates:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.intransitionmovie.com/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.intransitionmovie.com/&lt;/a&gt; -- Gandi commercial certificate and dedicated IP address
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.reconomy.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.reconomy.org/&lt;/a&gt; -- CAcert non-commercial certificate and shared IP address (SNI)
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.earthinheritors.net/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.earthinheritors.net/&lt;/a&gt; -- CAcert non-commercial certificate and shared IP address (SNI)
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://parrot.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://parrot.transitionnetwork.org/&lt;/a&gt; -- Gandi TN wild card cert and shared IP address (SNI)
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://parrot.webarch.net/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://parrot.webarch.net/&lt;/a&gt; -- CAcert non-commercial certificate, this is the default site for clients without SNI support
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
None of the site are set to enforce HTTPS for logins, this should be done ASAP for intransitionmovie.com
&lt;/p&gt;
&lt;p&gt;
I think we have several options going forward, the first 3 of this are the only viable ones though, IMHO:
&lt;/p&gt;
&lt;h2 id="SNIandSeperateCertsandSharedIP"&gt;SNI and Seperate Certs and Shared IP&lt;/h2&gt;
&lt;p&gt;
Get a Gandi SSL cert for each site and rely on SNI rather than having a dedicated IP address for each site, this is the cheapest way to solve the problem, the certs are around £15 each.
&lt;/p&gt;
&lt;p&gt;
The clients that don't work with SNI are listed here: &lt;a class="ext-link" href="https://en.wikipedia.org/wiki/Server_Name_Indication#Client_side"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://en.wikipedia.org/wiki/Server_Name_Indication#Client_side&lt;/a&gt;
&lt;/p&gt;
&lt;h2 id="Multi-domainCertandSharedIP"&gt;Multi-domain Cert and Shared IP&lt;/h2&gt;
&lt;p&gt;
Get a Gandi SSL cert with all the domains in, this is a little more expensive than seperate certs (around £20 per site) but it means that all the clients that don't work with SNI will work. One issue with this is when adding new site is that a brand new cert would be needed as additional names can't be added to multi-domain certs during their lifetime, this could be worked around by getting a single domain cert to run to the end of the life of the multi domain cert (this would use SNI).
&lt;/p&gt;
&lt;h2 id="SeperateCertsandDedicatedIPs"&gt;Seperate Certs and Dedicated IPs&lt;/h2&gt;
&lt;p&gt;
Getting a cert per site and a dedicated IP per site, this would cost the most as each IP address costs around the same as each cert, (so about £30 per site). It also seems like a great waste to use up a IP per site when they are so scarce and when technical workarounds to this old problem like multi-domain certs and SNI are now available. I don't favour this option.
&lt;/p&gt;
&lt;h2 id="Non-commercialCAcertCert"&gt;Non-commercial CAcert Cert&lt;/h2&gt;
&lt;p&gt;
This is the cheapest, it's fine if people are able to install the &lt;a class="ext-link" href="http://cacert.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://cacert.org/&lt;/a&gt; root certificate but this is something that non-technical people seem to find hard and they also don't understand the security warnings that they get when the cert isn't installed. This option is the one currently in use but it's far from ideal and one of the other options needs to be adopted before enforcing HTTPS logins is deployed. I don't favour this option.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/540#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/603</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/603</guid>
        <title>#603: Forwarding newsletter sends wrong message</title>
        <pubDate>Thu, 03 Oct 2013 09:24:09 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
User forwarded newsletter to themself (other email account) and was sent the wrong message - from a different user to someone else. See forwarded mail below.
&lt;/p&gt;
&lt;p&gt;
Please consider.
&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;
From: Jeanne &amp;lt;mackeyj@…&amp;gt;
Date: Mon, Sep 9, 2013 at 11:57 AM
Subject: Jeanne is forwarding an email to you
To: jeano &amp;lt;jmackey50@…&amp;gt;
&lt;/p&gt;
&lt;p&gt;
Hi Will Sutherland,
&lt;/p&gt;
&lt;p&gt;
Kathleen L thought you'd be interested in this:
&lt;a class="ext-link" href="http://us1.forward-to-friend2.com/forward/show?u=766036b57dc1247e2964584bd&amp;amp;id=7b4f6d65d1"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://us1.forward-to-friend2.com/forward/show?u=766036b57dc1247e2964584bd&amp;amp;id=7b4f6d65d1&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Kathleen L also included this personal message to you:
&lt;/p&gt;
&lt;p&gt;
more info for ya about Transition Towns - made me think of your game with their new book and ingredients and stuff - read about it...
Did you find the link interesting?
&lt;/p&gt;
&lt;p&gt;
You can forward it on to your friends, too:
&lt;a class="ext-link" href="http://us1.forward-to-friend2.com/forward?u=766036b57dc1247e2964584bd&amp;amp;id=7b4f6d65d1"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://us1.forward-to-friend2.com/forward?u=766036b57dc1247e2964584bd&amp;amp;id=7b4f6d65d1&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
You can subscribe for more emails at:
&lt;a class="ext-link" href="http://transitionnetwork.us1.list-manage1.com/subscribe?u=766036b57dc1247e2964584bd&amp;amp;id=33e8648c8d"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://transitionnetwork.us1.list-manage1.com/subscribe?u=766036b57dc1247e2964584bd&amp;amp;id=33e8648c8d&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Note: if any of the URLs above are not clickable, you can copy/paste them into your web browser.
&lt;/li&gt;&lt;/ul&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/603#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/606</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/606</guid>
        <title>#606: Site upgrade tasks -- pre-migration cleanup</title>
        <pubDate>Fri, 11 Oct 2013 12:00:13 GMT</pubDate>
        
        <dc:creator>jim</dc:creator>

        <description>&lt;p&gt;
This ticket is to track the issues left over from &lt;a class="assigned ticket" href="http://localhost:8080/trac/ticket/590" title="defect: Drupal performance improvements (assigned)"&gt;#590&lt;/a&gt; that need to be considered and tackled prior to migrating the site from D6 to D7 (or 8).
&lt;/p&gt;
&lt;p&gt;
Please feel free to add as needed, but sticky to the
&lt;/p&gt;
&lt;h2 id="CCleanup:Listoffeatureswedontreallyneed"&gt;C) Cleanup: List of features we don't really need&lt;/h2&gt;
&lt;p&gt;
Ed to add his items to following list... Need rational and alternative approaches for each.
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt;C.1) Remove 'Geographic region' and related taxonomy and Hierarchical Select modules&lt;/strong&gt; 1 hour, low reward, low risk -- never really been used and is effectively a duplicate of the location field. let's kill it!
&lt;/li&gt;&lt;li&gt;&lt;strong&gt;C.2) Kill Microsites and the Forums&lt;/strong&gt; -- The handful of people using the CMS feature should be migrated to Open Atrium if they need such features.
&lt;/li&gt;&lt;li&gt;&lt;strong&gt;C.3) Remove forums&lt;/strong&gt; --  We could migrate the forum to a simpler setup (not using forum module) that leverages normal commenting, or even Disqus or other services to offload comments and moderation. Also encourage user-submitted ocontent and promote that if it's good or gets interesting debate.
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="DKeydevelopmenttasks"&gt;D) Key development tasks&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt;D.1) All inline PHP must be moved to modules and features&lt;/strong&gt; -- This has great benefit for management, maintenance and developers. &lt;tt&gt;Eval()&lt;/tt&gt;uated code is much slower than PHP in files, especially since it can't be accelerated by APC or Zend Opcode cache... We have a few blocks and many views that are loaded from the database and evaluated. Ideally the blocks would be moved to the 'Transition Extras' module, and the views would be pushed into features. This work is good to do for maintainability and D7 upgrades, too. See: &lt;a class="ext-link" href="http://2bits.com/api/abuse-drupal-best-practices-your-own-peril-poor-performance.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://2bits.com/api/abuse-drupal-best-practices-your-own-peril-poor-performance.html&lt;/a&gt; and &lt;a class="ext-link" href="http://2bits.com/articles/free-your-content-php-moving-php-code-out-blocks-views-and-nodes.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://2bits.com/articles/free-your-content-php-moving-php-code-out-blocks-views-and-nodes.html&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;D.2) Build in ESI (Edge Side Includes) support from the outset, ensure Drupal renders only what it needs to &lt;/strong&gt; -- BOA packages the &lt;a class="ext-link" href="https://drupal.org/project/esi"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;ESI (Edge Side Includes integration) module&lt;/a&gt;, which makes NginX cache the whole page (as it does now), but also for user-logged in pages (which it does for 5 seconds since the page data changes). This means Drupal renders the ESI component (blocks, panels panes) that are have user-specific data in. Potential boost quickly, but will need time to tweak settings to get best from this across whole site. See &lt;a class="ext-link" href="https://tech.transitionnetwork.org/trac/ticket/590#comment:4"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;comments in 4 &amp;amp; 5 below for discussion&lt;/a&gt;&lt;del&gt;, should be done after proposal F, above&lt;/del&gt;.
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="EKeyeditorialtasks"&gt;E) Key editorial tasks&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt;E.1) More Taxonomy cleanup&lt;/strong&gt; -- try to merge terms with the same names, clear out spammy terms, general spit-and-polish. Ed plus team of busy interns to do this when the time is right.
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Zoldstuffforreferencetasksfrom590renderedpointlessbymove"&gt;Z) old stuff for reference; tasks from &lt;a class="assigned ticket" href="http://localhost:8080/trac/ticket/590" title="defect: Drupal performance improvements (assigned)"&gt;#590&lt;/a&gt; rendered pointless by move&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Z.1) Find Variable table writes and kill them&lt;/strong&gt; -- seeing plenty of SELECT * FROM variable calls, which imply a cache clear due to a variable being set. In normal use variables shouldn't be set (admin screens tend to do this), so I'd like to try to see what module it causing this and patch/remove it. Will need to run &lt;tt&gt;grep -R "variable_set() * &amp;gt; ~/static/variable_set-calls.txt" in the {{{sites/all&lt;/tt&gt; directory to generate a list, then trawl though it to find candidates/bad modules practice.
&lt;/li&gt;&lt;/ul&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/606#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/619</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/619</guid>
        <title>#619: Upgrade WordPress sites to 3.9.1</title>
        <pubDate>Fri, 15 Nov 2013 14:38:05 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
News regarding the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; versions released since the sites were upgraded to 3.6.1 on &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/594" title="maintenance: WordPress 3.6.1 Maintenance and Security Release (closed: fixed)"&gt;ticket:594&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://wordpress.org/news/2013/10/wordpress-3-7-1/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wordpress.org/news/2013/10/wordpress-3-7-1/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://wordpress.org/news/2013/10/basie/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wordpress.org/news/2013/10/basie/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
We should consider how best to upgrade the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;wiki:WordPress&lt;/a&gt; sites running on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;wiki:ParrotServer&lt;/a&gt; and then ensure that they are upgraded.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/619#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/626</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/626</guid>
        <title>#626: Add redirect from an old CMS to a new URL</title>
        <pubDate>Wed, 20 Nov 2013 12:11:14 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Can Ed add a redirect from:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/cms/haddenham"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/cms/haddenham&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
to another URL easily? Or does he need to ask Chris to do it?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/626#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/644</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/644</guid>
        <title>#644: AWstats Nginx config breaks aegir</title>
        <pubDate>Mon, 09 Dec 2013 16:46:05 GMT</pubDate>
        
        <dc:creator>jim</dc:creator>

        <description>&lt;p&gt;
Since the last update we've had a silent ngnix error that means &lt;a class="ext-link" href="http://tn.puffin.webarch.net"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://tn.puffin.webarch.net&lt;/a&gt; was not available.
&lt;/p&gt;
&lt;p&gt;
I restarted nginx and got:
&lt;/p&gt;
&lt;pre class="wiki"&gt;[  ok  ] Stopping Nginx Server...:
[ .... ] Starting Nginx Server...:nginx: [emerg] "log_format" directive is not allowed here in /etc/nginx/nginx.conf:28
&lt;/pre&gt;&lt;p&gt;
Which equates to the AWstats entry which is now commented out per:
&lt;/p&gt;
&lt;pre class="wiki"&gt;# log for awstats
#log_format apache '$remote_addr - $remote_user [$time_local] "$request" '
#                   '$status $body_bytes_sent "$http_referer" '
#                   '"$http_user_agent"';
#access_log         /var/log/nginx/awstats.log apache;
&lt;/pre&gt;&lt;p&gt;
I/we need access to aegir more than AWStats, so I've commented out the lines above and restarted nginx. Aegir is back and working well.
&lt;/p&gt;
&lt;p&gt;
This ticket is to find the correct log_format for modern nginx versions and reinstate AWstats -- assigning to Chris as a low priority thing.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/644#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/661</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/661</guid>
        <title>#661: Add button block to homepage RHS: Send us your news stories</title>
        <pubDate>Tue, 17 Dec 2013 15:34:53 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
January:
&lt;/p&gt;
&lt;p&gt;
Create button for TN homepage and /news and /blogs to encourage people to send in stories.
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;create button like the existing ones - e.g:
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/build/block/configure/block/89?destination=newhome"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/build/block/configure/block/89?destination=newhome&lt;/a&gt;
&lt;/p&gt;
&lt;ol start="2"&gt;&lt;li&gt;add suitably pithy text
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="3"&gt;&lt;li&gt;if in doubt about style, read Ben's style cheatsheet on google docs:
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
&lt;a class="ext-link" href="https://docs.google.com/document/d/1z6JYGiy8EJ6pqjm_WyNUS26fQgIClmIFg0a-8y-Mots/edit#heading=h.siua52eim2e9"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://docs.google.com/document/d/1z6JYGiy8EJ6pqjm_WyNUS26fQgIClmIFg0a-8y-Mots/edit#heading=h.siua52eim2e9&lt;/a&gt;
&lt;/p&gt;
&lt;ol start="4"&gt;&lt;li&gt;this will need to be an email forwarder to send to Rob instead of a http link as per the other buttons, so you'll need to set one up on United's dashboard using the main 'jmcgeechan' account
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
cc-ing benj as he can be around to help with postitioning/button make if an issue - but can't do email forwarder set up - and don't forget sam - if you're too busy you can always farm it out to ben (although this is probably a bit easy for ben, he'll know about how to get blocks in the right order)
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/661#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/671</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/671</guid>
        <title>#671: Replace core Search module with Apache Solr</title>
        <pubDate>Sat, 11 Jan 2014 21:11:14 GMT</pubDate>
        
        <dc:creator>jim</dc:creator>

        <description>&lt;p&gt;
&lt;strong&gt;Issue &amp;amp; background&lt;/strong&gt;
During work on &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/610" title="defect: Aegir database intensive (migrate, clone, restore) tasks hang for larger ... (closed: fixed)"&gt;#610&lt;/a&gt;, it was discovered that of a 1/4GB database dump for TN.org, ~80% (180Mb) of it was related to the Drupal 6 core Search module.
&lt;/p&gt;
&lt;p&gt;
It's worth noting &lt;a class="ext-link" href="https://tech.transitionnetwork.org/trac/ticket/516#comment:3"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;this&lt;/a&gt; was &lt;a class="ext-link" href="https://tech.transitionnetwork.org/trac/ticket/516#comment:6"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;raised&lt;/a&gt; when we migrated the site to the Puffin server in March 2013, but it's generally the case that the core Search module does not scale easily beyond a few thousand nodes.
&lt;/p&gt;
&lt;p&gt;
www.transitionnetwork.org has 23,803 nodes at time of writing -- this is probably approaching the sensible limit of the core module's capability.
&lt;/p&gt;
&lt;p&gt;
Note also, any future D7 or D8 version of the site would also hugely benefit from using Solr, so the server config part is time well spent.
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Proposed solution&lt;/strong&gt;
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;Add the Apache Solr option to BOA, re-run the installer to get it installed and configured automatically.
&lt;/li&gt;&lt;li&gt;Add the &lt;a class="ext-link" href="https://drupal.org/project/apachesolr"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;ApacheSolr module&lt;/a&gt; and any related required modules to the TN D6 makefile -- it's not clear if the 6.x-3.x branch or 6.x-1.x branch is the right choice at present.
&lt;/li&gt;&lt;li&gt;Build a new platform containing these modules, migrate a clone of STG to it.
&lt;/li&gt;&lt;li&gt;Enable the modules, configure them, disable core Search.
&lt;/li&gt;&lt;li&gt;Create a feature that wraps up config for Solr and required modules. Add to Git, add reference to feature to makefile
&lt;/li&gt;&lt;li&gt;Test, tweak, repeat 3 &amp;amp; 4 &amp;amp; 5 as needed.
&lt;/li&gt;&lt;li&gt;Migrate PROD to the new plaform, enabled feature, index site.
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
This could be parked until D7/8 migration, or not... Ed's call.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/671#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/675</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/675</guid>
        <title>#675: Piwik Geolocation</title>
        <pubDate>Tue, 14 Jan 2014 12:16:36 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
We have this warning in the Piwik admin interface:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Geolocation works, but you are not using one of the recommended providers. If you have to import log files or do something else that requires setting IP addresses, use the PECL GeoIP implementation (recommended) or the PHP GeoIP implementation.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
We currently do Geolocation at a Nginx level, it is possible that it would now be better to switch to do it at a Piwik level, see the documentation here: &lt;a class="ext-link" href="http://piwik.org/docs/geo-locate/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://piwik.org/docs/geo-locate/&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/675#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/689</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/689</guid>
        <title>#689: Duplicate comments</title>
        <pubDate>Fri, 14 Feb 2014 12:21:23 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi I got the below message from Mike. Paul could you take a look if you have a minute?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
&lt;p&gt;
I am noticing that many of the comments are being duplicated quite often - sometimes once and Rob's last comments was added twice. I've been deleting them but will be offline from now over the weekend.
&lt;/p&gt;
&lt;p&gt;
This article is getting lots of comments
&lt;a class="ext-link" href="https://www.transitionnetwork.org/blogs/rob-hopkins/2014-02/open-letter-bbc-lord-lawsons-today-programme-appearance"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/blogs/rob-hopkins/2014-02/open-letter-bbc-lord-lawsons-today-programme-appearance&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/689#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/690</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/690</guid>
        <title>#690: Paul learning the ways of the force.</title>
        <pubDate>Thu, 20 Feb 2014 15:00:41 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description>&lt;p&gt;
I'm not a jedi yet
&lt;/p&gt;
&lt;p&gt;
#### Transition Network
&lt;/p&gt;
&lt;p&gt;
Week ending 16 February
Monday (0,45) Phone call | Emails (not issues) | Creating a test site on Aeigr
Tuesday (0.45) Reading Wiki pages | Setting up local server (Generated notes for WIki)
Wednesday (0.45) Reading wiki pages: setting up a platform / cloning a stage site.
Friday (3.00) Reading wiki pages , listening to Jim's talks,  Emails (not issues). (Generated notes for WIki for setting up a local server)
&lt;/p&gt;
&lt;p&gt;
Finished reading wiki. I'll re-read these as required on my own time going forward.
&lt;/p&gt;
&lt;p&gt;
Week ending 23 February
Monday (0,15) Emails (not issues) (Mailing list)
Thursday (0,30) Phone call / Emails (not issues)
&lt;/p&gt;
&lt;p&gt;
Total 6, 00 hours
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/690#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/692</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/692</guid>
        <title>#692: Debian Updates</title>
        <pubDate>Tue, 25 Feb 2014 15:16:17 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
This is a ticket to track debian upgrades to the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt;, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer"&gt;wiki:PenguinServer&lt;/a&gt; and &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;wiki:ParrotServer&lt;/a&gt; the time they take.
&lt;/p&gt;
&lt;p&gt;
See:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://lists.debian.org/debian-security-announce/recent"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Recent Debian security announcements&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://lists.debian.org/debian-lts-announce/recent"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Recent Debian LTS security announcements&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://lists.askmonty.org/pipermail/announce/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;MariaDB Announce List archives&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://groups.google.com/group/phusion-passenger-announcements"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;phusion-passenger-announcements archive&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
These updates are generally done using the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/AptitudeUpdateScript"&gt;wiki:AptitudeUpdateScript&lt;/a&gt; and this records all the changes in the &lt;tt&gt;/root/Changelog&lt;/tt&gt; and then the contents of the Changelog are pasted into the ticket to document the upgrade.
&lt;/p&gt;
&lt;p&gt;
This ticket took over from &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/218" title="maintenance: Debian upgrades and updates (closed: fixed)"&gt;ticket:218&lt;/a&gt; on 2014-02-25.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/692#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/715</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/715</guid>
        <title>#715: Views admin pages not visible.</title>
        <pubDate>Tue, 08 Apr 2014 14:51:29 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi I just tried to access the views admin interface here: &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/build/views"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/build/views&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
It doesn't load the views admin pages, just an overview of the 'site building' pages instead.
&lt;/p&gt;
&lt;p&gt;
The page works as I expect it to on the stage site here: &lt;a class="ext-link" href="https://stg2.transitionnetwork.org/admin/build/views"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://stg2.transitionnetwork.org/admin/build/views&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
I have checked and the module is still enabled, The permissions look right (site admin is allowed to administer views: &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/user/permissions"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/user/permissions&lt;/a&gt;)
&lt;/p&gt;
&lt;p&gt;
Anyone got an idea whats going on?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/715#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/716</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/716</guid>
        <title>#716: Heartbleed</title>
        <pubDate>Wed, 09 Apr 2014 08:53:58 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Following on from &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/692#comment:18" title="maintenance: Debian Updates (new)"&gt;ticket:692#comment:18&lt;/a&gt; we should undertake the steps Drupal have taken: &lt;a class="ext-link" href="https://drupal.org/news/2014-04-08-security-update"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/news/2014-04-08-security-update&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/716#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/719</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/719</guid>
        <title>#719: Transition Culture HTML Problems</title>
        <pubDate>Mon, 14 Apr 2014 20:07:09 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
If you look at old Transition Culture articles they had hyperlinks and blockquotes, for example:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://web.archive.org/web/20070228081440/http://transitionculture.org/2006/01/24/local-energy-local-currency-local-power/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://web.archive.org/web/20070228081440/http://transitionculture.org/2006/01/24/local-energy-local-currency-local-power/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
If you look at the version we now have this formatting has been lost and the first paragraph is a mess:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://transitionculture.org/2006/01/24/local-energy-local-currency-local-power/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://transitionculture.org/2006/01/24/local-energy-local-currency-local-power/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
The formatting wasn't lost when the new TC design was first deployed:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://web.archive.org/web/20080429205320/http://transitionculture.org/2006/01/24/local-energy-local-currency-local-power/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://web.archive.org/web/20080429205320/http://transitionculture.org/2006/01/24/local-energy-local-currency-local-power/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
It has happened since then.
&lt;/p&gt;
&lt;p&gt;
We should consider investigating what caused the problems and how they can be fixed?
&lt;/p&gt;
&lt;p&gt;
This might be a task that Simon would be best placed to undertake?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/719#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/731</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/731</guid>
        <title>#731: Meetings in maintenance</title>
        <pubDate>Fri, 23 May 2014 10:47:39 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Ticket to record time spent on Skype call on 22nd May 2014.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/731#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/734</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/734</guid>
        <title>#734: Create Trac &amp; Wiki account for Annesley</title>
        <pubDate>Tue, 03 Jun 2014 11:04:10 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
email: Annesley Newholm &amp;lt;annesley.newholm@…&amp;gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/734#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/740</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/740</guid>
        <title>#740: Add 'class button block' to Soundcloud block</title>
        <pubDate>Thu, 12 Jun 2014 09:55:05 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Ben
&lt;/p&gt;
&lt;p&gt;
Could you add 'class button block' to the block class settings for this block:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/build/block/configure/block/98?destination=blogs%2Frob-hopkins"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/build/block/configure/block/98?destination=blogs%2Frob-hopkins&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Or shall I give myself 'developer' permissions so I can add these myself?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/740#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/741</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/741</guid>
        <title>#741: Views editor disappears in backend</title>
        <pubDate>Thu, 12 Jun 2014 10:42:13 GMT</pubDate>
        
        <dc:creator>annesley</dc:creator>

        <description>&lt;p&gt;
admin &amp;gt; views &amp;gt; edit
the view editor interface appears and then disappears immediately
this happens in Chrome / Ubuntu and Firefox / Mac
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/741#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/742</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/742</guid>
        <title>#742: Stg site to play with</title>
        <pubDate>Thu, 12 Jun 2014 14:35:42 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Paul
&lt;/p&gt;
&lt;p&gt;
I'm trying to set up a stage site, just to test rearranging the homepage blocks.
&lt;/p&gt;
&lt;p&gt;
I created a site on the "Transition Network D6 S012 Booker" Platform, but I just get an empty pressflow site: &lt;a class="ext-link" href="http://stgsam.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://stgsam.transitionnetwork.org/&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Can I use your stg site to test the block arrangement instead: &lt;a class="ext-link" href="https://booker-stage-20140501.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://booker-stage-20140501.transitionnetwork.org/&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Or could you let me know what might be going wrong?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/742#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/746</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/746</guid>
        <title>#746: New comment notifications not being sent to content owners.</title>
        <pubDate>Tue, 24 Jun 2014 09:27:11 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Paul, Annesley, Chris
&lt;/p&gt;
&lt;p&gt;
Ed hasn't been getting notifications for new comments.
&lt;/p&gt;
&lt;p&gt;
"Please check if new comment notifications are being sent to content owners. I don’t think I am receiving email alerts for my blog posts."
&lt;/p&gt;
&lt;p&gt;
I'll email Rob to see if he's getting any.
&lt;/p&gt;
&lt;p&gt;
Could you investigate?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/746#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/747</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/747</guid>
        <title>#747: Accessibility / archiving of podcasts</title>
        <pubDate>Tue, 24 Jun 2014 10:39:14 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Would it be possible to consider making podcasts available as MP3's via RSS feeds? This would enable applications such as &lt;a class="ext-link" href="https://f-droid.org/wiki/page/de.danoeh.antennapod"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;AntennaPod&lt;/a&gt; to play the podcasts.
&lt;/p&gt;
&lt;p&gt;
Currently podcasts such as this one:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.transitionnetwork.org/blogs/rob-hopkins/2014-06/alan-simpson-transition-has-enormous-strength-moment"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/blogs/rob-hopkins/2014-06/alan-simpson-transition-has-enormous-strength-moment&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Appear to only be available via the Soundcloud web interface?
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://soundcloud.com/transition-culture/alan-simpson-on-growth-renewables-and-transition"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://soundcloud.com/transition-culture/alan-simpson-on-growth-renewables-and-transition&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
There might be Soundcloud settings to enable MP3 downloads and / or RSS feeds?
&lt;/p&gt;
&lt;p&gt;
In addition having a copies available / archived on a non-corporate site, eg a *.transitionnetwork.org site and / or archive.org would be a good addition?
&lt;/p&gt;
&lt;p&gt;
Sorry if this isn't the right place to raise this, I did consider posting it as a comment on Robs blog but thought that would be even less appropriate.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/747#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/750</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/750</guid>
        <title>#750: Annual update of SSL cert fingerprint for incomming emails to Trac</title>
        <pubDate>Thu, 26 Jun 2014 13:42:42 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Laura said she had replied to Trac email today but they didn't get through.
&lt;/p&gt;
&lt;p&gt;
The issues has come up before, see &lt;a class="wiki" href="http://localhost:8080/trac/wiki/TransitionTrac#Fetchmail"&gt;wiki:TransitionTrac#Fetchmail&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/750#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/757</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/757</guid>
        <title>#757: Research and Design for TNv3</title>
        <pubDate>Fri, 11 Jul 2014 13:36:54 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
R&amp;amp;D for TNv3
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/757#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/759</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/759</guid>
        <title>#759: [Security-news] SA-CONTRIB-2014-071 - FileField - Access bypass</title>
        <pubDate>Wed, 16 Jul 2014 21:59:46 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description>&lt;p&gt;
View online: &lt;a class="ext-link" href="https://www.drupal.org/node/2304561"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/node/2304561&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Advisory ID: DRUPAL-SA-CONTRIB-2014-071
&lt;/li&gt;&lt;li&gt;Project: &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; (third-party module)
&lt;/li&gt;&lt;li&gt;Version: 6.x
&lt;/li&gt;&lt;li&gt;Date: 2014-July-16
&lt;/li&gt;&lt;li&gt;Security risk: Critical &lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Exploitable from: Remote
&lt;/li&gt;&lt;li&gt;Vulnerability: Access bypass
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
The &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; module enables you to define and use fields that contain files.
&lt;/p&gt;
&lt;p&gt;
The module doesn't sufficiently check permission to view the attached file
when attaching a file that was previously uploaded. This could allow
attackers to gain access to private files.
&lt;/p&gt;
&lt;p&gt;
This vulnerability is mitigated by the fact that the attacker must have
permission to create or edit content with a file field.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;/A CVE identifier &lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; will be requested, and added upon issuance, in
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
accordance with Drupal Security Team processes./
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; 6.x-3.x versions prior to 6.x-3.13.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Drupal core is not affected. If you do not use the contributed &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt;
module, there is nothing you need to do.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;If you use the &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; module for Drupal 6.x, upgrade to Filefield
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
6.x-3.13 &lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt;, and also update to Drupal core 6.32 &lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt; (see
SA-CORE-2014-003 &lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt;).
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Ivan Ch &lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Nate Haug &lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Ivan Ch &lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;David Snopek &lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; of the Drupal Security Team.
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
The Drupal security team can be reached at security at drupal.org or via the
contact form at &lt;a class="ext-link" href="http://drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/contact&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Learn more about the Drupal Security team and their policies &lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt;, writing
secure code for Drupal &lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt;, and securing your site &lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Follow the Drupal Security Team on Twitter at
&lt;a class="ext-link" href="https://twitter.com/drupalsecurity"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://twitter.com/drupalsecurity&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/project/filefield"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/filefield&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team/risk-levels"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team/risk-levels&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; &lt;a class="ext-link" href="http://cve.mitre.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://cve.mitre.org/&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/project/filefield"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/project/filefield&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/node/2304517"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/node/2304517&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/drupal-6.32-release-notes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/drupal-6.32-release-notes&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/SA-CORE-2014-003"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/SA-CORE-2014-003&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/556138"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/556138&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/35821"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/35821&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/556138"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/556138&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/266527"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/266527&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/contact&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/writing-secure-code"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/writing-secure-code&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security/secure-configuration"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security/secure-configuration&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt; &lt;a class="ext-link" href="https://twitter.com/drupalsecurity"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://twitter.com/drupalsecurity&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;_
Security-news mailing list
Security-news@…
Unsubscribe at &lt;a class="ext-link" href="https://lists.drupal.org/mailman/listinfo/security-news"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://lists.drupal.org/mailman/listinfo/security-news&lt;/a&gt;
&lt;/span&gt;&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/759#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/761</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/761</guid>
        <title>#761: Spam account cull</title>
        <pubDate>Thu, 17 Jul 2014 08:45:33 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
There are bucketloads of spam accounts swamping us. Spam commeting is swarming again. I just did several pages of deleting spam accounts.  No doubt I nailed some humans too (sorry Sam if this comes back to you); but the overwhelming majority of new accounts are spam.
&lt;/p&gt;
&lt;p&gt;
It's crap and we need to have another spam sweep - especially if we're staying in D6 for a while.
&lt;/p&gt;
&lt;p&gt;
See work done in Feb 2013: &lt;a class="assigned ticket" href="http://localhost:8080/trac/ticket/461" title="enhancement: Spam account war (assigned)"&gt;#461&lt;/a&gt;
See wiki page done in Feb 2013: &lt;a class="ext-link" href="https://wiki.transitionnetwork.org/Spam_accounts"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.transitionnetwork.org/Spam_accounts&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
SAM I'm going to suggest you start looking at it, and get your head around it, and the various modules and processes we've got running, then ask you to act/escalate accordingly.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/761#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/763</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/763</guid>
        <title>#763: Server Backups</title>
        <pubDate>Mon, 21 Jul 2014 17:09:21 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Two weeks ago &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/754#comment:21" title="maintenance: Can we upgrade from PHP 5.3? (closed: wontfix)"&gt;annesley asked&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
what off-site data storage, file backup and quick setup do we have?
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/754#comment:22" title="maintenance: Can we upgrade from PHP 5.3? (closed: wontfix)"&gt;answered&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
The 3 virtual servers have their file system mounted off a BSD/NFS/ZFS file server and the whole file system is backed up and stored onto another BSD/ZFS server in the same data centre. We did have backups also being copied to a server in Manchester but this is currently off-line as the Manchester server needs a disk swapping and rebuilding as a BSD/ZFS server.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
A problem with this is that it's only me and Alan that have access to these backups, so I'd like to suggest I set up a new account for backups on our backup server and sort out cron jobs to rsync data to this account and document how people can access these backups.
&lt;/p&gt;
&lt;p&gt;
The result would be that everybody would have SFTP access to 60 days worth of snapshots of backups from all three servers whenever needed without any need for my or Alan's intervention.
&lt;/p&gt;
&lt;p&gt;
I expect this would take abount an hour to set up and another hour to document and help people understand it.
&lt;/p&gt;
&lt;p&gt;
There would be no additional cost to the TN because backup space is already paid for.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/763#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/764</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/764</guid>
        <title>#764: Policy decisions re-assessment on BOA and Drupal security updates</title>
        <pubDate>Tue, 22 Jul 2014 14:10:38 GMT</pubDate>
        
        <dc:creator>annesley</dc:creator>

        <description>&lt;p&gt;
on-line meeting 5 / August @ 14:00 GMT:
we are phasing out the current D6 / BOA system. the new system may not use either. The TN.org website is not attractive to high level hackers or DOS attacks.
&lt;/p&gt;
&lt;p&gt;
what are the risks with cancelling all further Unix, BOA and Drupal updates completely that do not allow direct un-mitigated access to the backend via bad PHP code / SQL?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/764#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/767</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/767</guid>
        <title>#767: robots.txt on dev site</title>
        <pubDate>Thu, 31 Jul 2014 11:07:39 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Paul
&lt;/p&gt;
&lt;p&gt;
Could you fix the robots.txt here:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://booker-stage-20140501.transitionnetwork.org/robots.txt"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://booker-stage-20140501.transitionnetwork.org/robots.txt&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Ta
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/767#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/768</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/768</guid>
        <title>#768: Piwik Archive Cron Error</title>
        <pubDate>Fri, 01 Aug 2014 17:14:59 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Have been getting these emails from &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PiwikServer"&gt;PiwikServer&lt;/a&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;From: root@penguin.webarch.net (Cron Daemon)
Date: Fri,  1 Aug 2014 14:06:48 +0100 (BST)
To: root@localhost
Subject: Cron &amp;lt;www-data@penguin&amp;gt; /web/stats.transitionnetwork.org/piwik/console core:archive --url=http://stats.transitionnetwork.org/ &amp;gt; /var/log/piwik-archive.log
ERROR CoreConsole[2014-08-01 13:05:18] [3e5ac] Got invalid response from API request:
+http://stats.transitionnetwork.org/index.php?module=API&amp;amp;method=API.get&amp;amp;idSite=1&amp;amp;period=week&amp;amp;date=last2&amp;amp;format=php&amp;amp;token_auth=XXXXXXXXXXXX&amp;amp;trigger=archivephp. Response was ' &amp;lt;div style='word-wrap: break-word; border: 3px solid red; padding:4px; width:70%;
+background-color:#FFFF96;'&amp;gt;         &amp;lt;strong&amp;gt;There is an error. Please report the message (Piwik 2.4.1)         and full backtrace in the &amp;lt;a
+href='?module=Proxy&amp;amp;action=redirect&amp;amp;url=http://forum.piwik.org' target='_blank'&amp;gt;Piwik forums&amp;lt;/a&amp;gt; (please do a Search first as it might have
+been reported already!).&amp;lt;br /&amp;gt;&amp;lt;br/&amp;gt;         Warning:&amp;lt;/strong&amp;gt;
+&amp;lt;em&amp;gt;file_get_contents(http://api.piwik.org/1.0/getLatestVersion/?piwik_version=2.4.1&amp;amp;php_version=5.4.4-14%2Bdeb7u12&amp;amp;url=https%3A%2F%2Fstats.
+transitionnetwork.org%2Fweb%2Fstats.transitionnetwork.org%2Fpiwik%2Fconsole&amp;amp;trigger=API&amp;amp;timezone=Europe%2FLondon): failed to open stream:
+HTTP requ
 est fail
 ed! &amp;lt;/em&amp;gt; in &amp;lt;strong&amp;gt;/web/stats.transitionnetwork.org/piwik/core/Http.php&amp;lt;/strong&amp;gt; on line &amp;lt;strong&amp;gt;406&amp;lt;/strong&amp;gt; &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Backtrace
+--&amp;amp;gt;&amp;lt;div style="font-family:Courier;font-size:10pt"&amp;gt;&amp;lt;br /&amp;gt; #0  Piwik\Error::errorHandler(...) called at [:]&amp;lt;br /&amp;gt; #1
+file_get_contents(...) called at [/web/stats.transitionnetwork.org/piwik/core/Http.php:406]&amp;lt;br /&amp;gt; #2  Piwik\Http::sendHttpRequestBy(...)
+called at [/web/stats.transitionnetwork.org/piwik/core/Http.php:94]&amp;lt;br /&amp;gt; #3  Piwik\Http::sendHttpRequest(...) called at
+[/web/stats.transitionnetwork.org/piwik/core/UpdateCheck.php:72]&amp;lt;br /&amp;gt; #4  Piwik\UpdateCheck::check(...) called at
+[/web/stats.transitionnetwork.org/piwik/plugins/CoreUpdater/CoreUpdater.php:142]&amp;lt;br /&amp;gt; #5
+Piwik\Plugins\CoreUpdater\CoreUpdater-&amp;gt;updateCheck(...) called at [:]&amp;lt;br /&amp;gt; #6  call_user_func_array(...) called at
+[/web/stats.transitionnetwork.org/piwik/core/EventDispatcher.php:98]&amp;lt;br /&amp;gt; #7  Piwik\EventDispatcher-&amp;gt;postEvent(...) called at
+[/web/stats.transitionnetwor
 k.org/pi
 wik/core/Piwik.php:766]&amp;lt;br /&amp;gt; #8  Piwik\Piwik::postEvent(...) called at
+[/web/stats.transitionnetwork.org/piwik/core/FrontController.php:391]&amp;lt;br /&amp;gt; #9  Piwik\FrontController-&amp;gt;init(...) called at
+[/web/stats.transitionnetwork.org/piwik/core/dispatch.php:33]&amp;lt;br /&amp;gt; #10  require_once(...) called at
+[/web/stats.transitionnetwork.org/piwik/index.php:47]&amp;lt;br /&amp;gt; #11  require_once(...) called at
+[/web/stats.transitionnetwork.org/piwik/core/CliMulti/RequestCommand.php:53]&amp;lt;br /&amp;gt; #12  Piwik\CliMulti\RequestCommand-&amp;gt;execute(...) called
+at [/web/stats.transitionnetwork.org/piwik/vendor/symfony/console/Symfony/Component/Console/Command/Command.php:252]&amp;lt;br /&amp;gt; #13
+Symfony\Component\Console\Command\Command-&amp;gt;run(...) called at
+[/web/stats.transitionnetwork.org/piwik/vendor/symfony/console/Symfony/Component/Console/Application.php:887]&amp;lt;br /&amp;gt; #14
+Symfony\Component\Console\Application-&amp;gt;doRunCommand(...) called at
+[/web/stats.transitionnetwork.org/piwik/vendor/symfony/console/Symfony/Component/Co
 nsole/Ap
 plication.php:193]&amp;lt;br /&amp;gt; #15  Symfony\Component\Console\Application-&amp;gt;doRun(...) called at
+[/web/stats.transitionnetwork.org/piwik/core/Console.php:64]&amp;lt;br /&amp;gt; #16  Piwik\Console-&amp;gt;doRun(...) called at
+[/web/stats.transitionnetwork.org/piwik/vendor/symfony/console/Symfony/Component/Console/Application.php:124]&amp;lt;br /&amp;gt; #17
+Symfony\Component\Console\Application-&amp;gt;run(...) called at [/web/stats.transitionnetwork.org/piwik/console:31]&amp;lt;br /&amp;gt; &amp;lt;/div&amp;gt;&amp;lt;br /&amp;gt;
+&amp;lt;/pre&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;br /&amp;gt;  &amp;lt;div style='word-wrap: break-word; border: 3px solid red; padding:4px; width:70%; background-color:#FFFF96;'&amp;gt;
+&amp;lt;strong&amp;gt;There is an error. Please report the message (Piwik 2.4.1)         and full backtrace in the &amp;lt;a
+href='?module=Proxy&amp;amp;action=redirect&amp;amp;url=http://forum.piwik.org' target='_blank'&amp;gt;Piwik forums&amp;lt;/a&amp;gt; (please do a Search first as it might have
+been reported already!).&amp;lt;br /&amp;gt;&amp;lt;br/&amp;gt;         Warning:&amp;lt;/strong&amp;gt;
+&amp;lt;em&amp;gt;file_get_contents(http://api.piwik.org/1.0/getLatestVersion/?piwik_version=2.4.1&amp;amp;php_version
 =5.4.4-1
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/768#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/783</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/783</guid>
        <title>#783: IIRS design and development</title>
        <pubDate>Mon, 08 Sep 2014 14:20:58 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Ticket to track ongoing work on IIRS
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/783#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/787</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/787</guid>
        <title>#787: Access to Parrot</title>
        <pubDate>Mon, 15 Sep 2014 07:21:51 GMT</pubDate>
        
        <dc:creator>annesley</dc:creator>

        <description>&lt;p&gt;
is it ok for me to send through my normal, non-passphrase protected public key to you Chris for parrot?
&lt;/p&gt;
&lt;p&gt;
the documentation wants a passphrase protected key. however this may be what is causing the access issues from my laptop. i certainly could find a way around it but would suggest that the passphrase is not a great improvement to security anyway in this instance so it would be ok to use my normal public key. note that i can access all my other servers with the normal key without problems.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/787#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/789</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/789</guid>
        <title>#789: SA-CONTRIB-2014-088 - Mollom - Cross-site scripting (XSS)</title>
        <pubDate>Mon, 22 Sep 2014 13:09:48 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description>&lt;p&gt;
View online: &lt;a class="ext-link" href="https://www.drupal.org/node/2340029"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/node/2340029&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Advisory ID: DRUPAL-SA-CONTRIB-2014-088
&lt;/li&gt;&lt;li&gt;Project: Mollom &lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; (third-party module)
&lt;/li&gt;&lt;li&gt;Version: 6.x, 7.x
&lt;/li&gt;&lt;li&gt;Date: 2014-September-17
&lt;/li&gt;&lt;li&gt;Security risk: 11/25 ( Moderately Critical)
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:Uncommon &lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Vulnerability: Cross Site Scripting
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
Mollom is an "intelligent" content moderation web service which determines if
a post is potentially spam; not only based on the posted content, but also on
the past activity and reputation of the poster across multiple sites.
&lt;/p&gt;
&lt;p&gt;
Mollom offers a feature to report submitted content as inappropriate which
allows end users to indicate that a piece of site content is objectionable or
out of place. When reporting content, the content title is not sufficiently
sanitized to prevent cross-site scripting (XSS) attacks.
&lt;/p&gt;
&lt;p&gt;
This vulnerability is mitigated by the fact that an attacker must have a role
with the permission to create content and the content type must be enabled
for "Flag as Inappropriate" within the Mollom advanced configuration settings
(which is not the default setting).
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;/A CVE identifier &lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; will be requested, and added upon issuance, in
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
accordance
with Drupal Security Team processes./
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Mollom 6.x-2.x versions from 6.x-2.7 to 6.x-2.10
&lt;/li&gt;&lt;li&gt;Mollom 7.x-2.x versions from 7.x-2.9 to 7.x-2.10
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Drupal core is not affected. If you do not use the contributed Mollom &lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt;
module,
there is nothing you need to do.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
Install the latest version:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;If you use the Mollom module for Drupal 6.x, upgrade to Mollom 6.x-2.11
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;If you use the Mollom module for Drupal 7.x, upgrade to Mollom 7.x-2.11
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Also see the Mollom &lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt; project page.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Matt Vance &lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Lisa Backer &lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt; the module maintainer
&lt;/li&gt;&lt;li&gt;Matt Vance &lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Greg Knaddison &lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
The Drupal security team can be reached at security at drupal.org or via the
contact form at &lt;a class="ext-link" href="https://www.drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/contact&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Learn more about the Drupal Security team and their policies &lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt;,
writing secure code for Drupal &lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt;, and
securing your site &lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/project/mollom"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/mollom&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/security-team/risk-levels"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/security-team/risk-levels&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; &lt;a class="ext-link" href="http://cve.mitre.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://cve.mitre.org/&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/project/mollom"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/mollom&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/node/2338787"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/node/2338787&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/node/2338789"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/node/2338789&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/project/mollom"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/mollom&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/88338"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/88338&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/1951462"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/1951462&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/88338"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/88338&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/36762"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/36762&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/contact&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/security-team"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/security-team&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/writing-secure-code"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/writing-secure-code&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/security/secure-configuration"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/security/secure-configuration&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/789#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/790</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/790</guid>
        <title>#790: Annesley locked out of puffin</title>
        <pubDate>Tue, 23 Sep 2014 14:05:18 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email from lfd:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Time:     Tue Sep 23 13:47:01 2014 +0100
IP:       XX.XX.XX.XX (HU/Hungary/XXXXXX.catv.pool.telekom.hu)
Failures: 5 (sshd)
Interval: 300 seconds
Blocked:  Permanent Block
Log entries:
Sep 23 13:46:28 puffin sshd[6056]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=XX.XX.XX.XX  user=tn.ftp
Sep 23 13:46:30 puffin sshd[6056]: Failed password for tn.ftp from XX.XX.XX.XX port 54327 ssh2
Sep 23 13:46:33 puffin sshd[6056]: Failed password for tn.ftp from XX.XX.XX.XX port 54327 ssh2
Sep 23 13:46:56 puffin sshd[6409]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=XX.XX.XX.XX  user=anewholm
Sep 23 13:46:58 puffin sshd[6409]: Failed password for anewholm from XX.XX.XX.XX port 54328 ssh2
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/790#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/792</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/792</guid>
        <title>#792: [Security-news] SA-CONTRIB-2014-094 - Webform Patched - Cross Site Scripting (XSS)</title>
        <pubDate>Mon, 29 Sep 2014 09:28:08 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description>&lt;p&gt;
View online: &lt;a class="ext-link" href="https://www.drupal.org/node/2344369"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/node/2344369&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Advisory ID: DRUPAL-SA-CONTRIB-2014-094
&lt;/li&gt;&lt;li&gt;Project: Webform Patched &lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; (third-party module)
&lt;/li&gt;&lt;li&gt;Version: 6.x, 7.x
&lt;/li&gt;&lt;li&gt;Date: 2014-September-24
&lt;/li&gt;&lt;li&gt;Security risk: 13/25 ( Moderately Critical)
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default &lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Vulnerability: Cross Site Scripting
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
The Webform Patched module is a fork of the Webform module with Token support
added. The module enables you to create forms which can be used for surveys,
contact forms or other data collection throughout your site.
&lt;/p&gt;
&lt;p&gt;
The module doesn't sufficiently sanitize field label titles when two fields
have the same form_key, which can only be managed by carefully crafting the
webform structure via a specific set of circumstances.
&lt;/p&gt;
&lt;p&gt;
This vulnerability is mitigated by the fact that an attacker must have a role
with the permission "create webform content".
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;/A CVE identifier &lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; will be requested, and added upon issuance, in
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
accordance
with Drupal Security Team processes./
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Webform Patched 6.x-3.x versions prior to 6.x-3.20.
&lt;/li&gt;&lt;li&gt;Webform Patched 7.x-3.x versions prior to 7.x-3.20.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Drupal core is not affected. If you do not use the contributed Webform
Patched &lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt; module,
there is nothing you need to do.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
Install the latest version:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;If you use the webform module for Drupal 6.x, upgrade to webform_patched
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
6.x-3.20 &lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;If you use the webform module for Drupal 7.x-3.x, upgrade to
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
webform_patched 7.x-3.20 &lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Also see the Webform Patched &lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt; project page.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Maurits Lawende &lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Matt Vance &lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Nate Haug &lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt; the module maintainer
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Greg Knaddison &lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt;, Dan Smith &lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt; and Lee Rowlands &lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt; of the Drupal
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Security Team
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
The Drupal security team can be reached at security at drupal.org or via the
contact form at
&lt;a class="ext-link" href="https://www.drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/contact&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Learn more about the Drupal Security team and their policies &lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt;,
writing secure code for Drupal &lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt;, and
securing your site &lt;a class="missing changeset" title="No default repository defined"&gt;[17]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/project/webform_patched"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/webform_patched&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/security-team/risk-levels"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/security-team/risk-levels&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; &lt;a class="ext-link" href="http://cve.mitre.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://cve.mitre.org/&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/project/webform_patched"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/webform_patched&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/node/2241675"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/node/2241675&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/node/2241685"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/node/2241685&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/project/webform_patched"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/webform_patched&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/user/243897"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/user/243897&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/10269"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/10269&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/user/35821"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/user/35821&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/user/36762"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/user/36762&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/user/241220"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/user/241220&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt; &lt;a class="ext-link" href="https://drupal.org/user/395439"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/user/395439&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/contact&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/security-team"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/security-team&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/writing-secure-code"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/writing-secure-code&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[17]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/security/secure-configuration"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/security/secure-configuration&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/792#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/794</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/794</guid>
        <title>#794: Time estimate: change TN.org background image</title>
        <pubDate>Fri, 10 Oct 2014 09:06:29 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Rob is thinking about doing a 1970s editorial month, and would like a 1970s style 'naff' wallpaper.
&lt;/p&gt;
&lt;p&gt;
Ben please can you provide a time estimate for replacing the tasteful blue dotty background with some semi-transparent paisley thing for a month, and then reverting to the tasteful blue dots
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/794#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/804</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/804</guid>
        <title>#804: Investigating the site security following SA-CORE-2014-005 (Drupal 7.32)</title>
        <pubDate>Mon, 03 Nov 2014 15:20:25 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description>&lt;p&gt;
It was discovered that TN could have have been compromised from the recent security vulnerability (even though we are running Drupal 6)
as the site is using the DBTNG module. However the site doesn't appear to have been compromised. I'll post my findings shortly.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/804#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/806</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/806</guid>
        <title>#806: IIRS pre-beta usability issues</title>
        <pubDate>Mon, 10 Nov 2014 21:30:27 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Ticket to track usability issues etc.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/806#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/808</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/808</guid>
        <title>#808: WordPress email being rejected due to From field</title>
        <pubDate>Mon, 17 Nov 2014 19:28:23 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
This issues is like &lt;a class="assigned ticket" href="http://localhost:8080/trac/ticket/737" title="maintenance: SPF / Emails rejected from the website contact form (assigned)"&gt;ticket:737&lt;/a&gt; but with &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; rather than Drupal causing the problem.
&lt;/p&gt;
&lt;p&gt;
Laura has forwarded one of the returned emails which contains:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
host aspmx.l.google.com [173.194.67.26]:
550-5.7.1 Unauthenticated email from yahoo.com is not accepted due to domain's
550-5.7.1 DMARC policy. Please contact administrator of yahoo.com domain if
550-5.7.1 this was a legitimate mail. Please visit
550-5.7.1 &lt;a class="ext-link" href="http://support.google.com/mail/answer/2451690"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://support.google.com/mail/answer/2451690&lt;/a&gt; to learn about DMARC
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/808#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/809</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/809</guid>
        <title>#809: [Security-news] Drupal Core - Moderately Critical - Multiple Vulnerabilities - SA-CORE-2014-006</title>
        <pubDate>Wed, 19 Nov 2014 21:35:25 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description>&lt;p&gt;
View online: &lt;a class="ext-link" href="https://www.drupal.org/SA-CORE-2014-006"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/SA-CORE-2014-006&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Advisory ID: DRUPAL-SA-CORE-2014-006
&lt;/li&gt;&lt;li&gt;Project: Drupal core &lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Version: 6.x, 7.x
&lt;/li&gt;&lt;li&gt;Date: 2014-November-19
&lt;/li&gt;&lt;li&gt;Security risk: 14/25 ( Moderately Critical)
AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:Uncommon &lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Vulnerability: Multiple vulnerabilities
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
.... Session hijacking (Drupal 6 and 7)
&lt;/p&gt;
&lt;p&gt;
A specially crafted request can give a user access to another user's session,
allowing an attacker to hijack a random session.
&lt;/p&gt;
&lt;p&gt;
This attack is known to be possible on certain Drupal 7 sites which serve
both HTTP and HTTPS content ("mixed-mode" &lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt;), but it is possible there are
other attack vectors for both Drupal 6 and Drupal 7.
&lt;/p&gt;
&lt;p&gt;
.... Denial of service (Drupal 7 only)
&lt;/p&gt;
&lt;p&gt;
Drupal 7 includes a password hashing API to ensure that user supplied
passwords are not stored in plain text.
&lt;/p&gt;
&lt;p&gt;
A vulnerability in this API allows an attacker to send specially crafted
requests resulting in CPU and memory exhaustion. This may lead to the site
becoming unavailable or unresponsive (denial of service).
&lt;/p&gt;
&lt;p&gt;
This vulnerability can be exploited by anonymous users.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;/A CVE identifier &lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt; will be requested, and added upon issuance, in
accordance
&lt;/li&gt;&lt;/ul&gt;&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;
with Drupal Security Team processes./
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Drupal core 6.x versions prior to 6.34.
&lt;/li&gt;&lt;li&gt;Drupal core 7.x versions prior to 7.34.
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
Install the latest version:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;If you use Drupal 6.x, upgrade to Drupal core 6.34. &lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;If you use Drupal 7.x, upgrade to Drupal core 7.34. &lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
If you have configured a custom password.inc file for your Drupal 7 site you
also need to make sure that it is not prone to the same denial of service
vulnerability.  See also the similar security advisory for the Drupal 6
contributed Secure Password Hashes module: SA-CONTRIB-2014-113 &lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Also see the Drupal core &lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt; project page.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
Session hijacking:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Aaron Averill &lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Denial of service:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Michael Cullum  &lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Javier Nieto &lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Andrés Rojas Guerrero &lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
Session hijacking:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Klaus Purer &lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;li&gt;David Rothstein &lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;li&gt;Peter Wolanin &lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Denial of service:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Klaus Purer &lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;li&gt;Peter Wolanin &lt;a class="missing changeset" title="No default repository defined"&gt;[17]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;li&gt;Heine Deelstra &lt;a class="missing changeset" title="No default repository defined"&gt;[18]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;li&gt;Tom Phethean &lt;a class="missing changeset" title="No default repository defined"&gt;[19]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;The Drupal Security Team
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
The Drupal security team can be reached at security at drupal.org or via the
contact form at &lt;a class="ext-link" href="https://www.drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/contact&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[20]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Learn more about the Drupal Security team and their policies &lt;a class="missing changeset" title="No default repository defined"&gt;[21]&lt;/a&gt;, writing
secure code for Drupal &lt;a class="missing changeset" title="No default repository defined"&gt;[22]&lt;/a&gt;, and  securing your site &lt;a class="missing changeset" title="No default repository defined"&gt;[23]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Follow the Drupal Security Team on Twitter at
&lt;a class="ext-link" href="https://twitter.com/drupalsecurity"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://twitter.com/drupalsecurity&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[24]&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/project/drupal"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/drupal&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/security-team/risk-levels"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/security-team/risk-levels&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/https-information"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/https-information&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt; &lt;a class="ext-link" href="http://cve.mitre.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://cve.mitre.org/&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/drupal-6.34-release-notes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/drupal-6.34-release-notes&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/drupal-7.34-release-notes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/drupal-7.34-release-notes&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/node/2378367"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/node/2378367&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/project/drupal"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/drupal&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/1317732"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/1317732&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/MichaelCu"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/MichaelCu&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/jnietotn"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/jnietotn&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/c0r3dump3d"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/c0r3dump3d&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/klausi"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/klausi&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/David_Rothstein"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/David_Rothstein&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/pwolanin"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/pwolanin&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/klausi"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/klausi&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[17]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/pwolanin"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/pwolanin&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[18]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/Heine"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/Heine&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[19]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/tsphethean"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/tsphethean&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[20]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/contact&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[21]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/security-team"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/security-team&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[22]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/writing-secure-code"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/writing-secure-code&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[23]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/security/secure-configuration"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/security/secure-configuration&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[24]&lt;/a&gt; &lt;a class="ext-link" href="https://twitter.com/drupalsecurity"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://twitter.com/drupalsecurity&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/809#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/812</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/812</guid>
        <title>#812: space.transitionnetwork.org hacked?</title>
        <pubDate>Thu, 27 Nov 2014 11:09:32 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
BOA email from &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;PuffinServer&lt;/a&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Hello,
Our system detected that the site space.transitionnetwork.org has been hacked!
Common signatures of an attack which triggered this alert:
You are required to change your password immediately (password aged)
su: Authentication token is no longer valid; new one required
(Ignored)
Site tested positive for known Drupalgeddon exploit checks               [error]
Update module is disabled and Drupalgeddon cannot check for Drupal       [error]
Security Updates. Please check for a security update manually.
You are running Drupal 7.31
https://www.drupal.org/node/3060/release?api_version%5B%5D=103
The platform root directory for this site is:
  /data/disk/tn/distro/008/openatrium-7.x-2.19-7.31.1
The system hostname is:
  puffin.webarch.net
To learn more on what happened, how it was possible and
how to survive #Drupageddon, please read:
  https://omega8.cc/drupageddon-psa-2014-003-342
--
This e-mail has been sent by your Aegir system monitor.
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/812#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/818</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/818</guid>
        <title>#818: For watch lovers. superwatches</title>
        <pubDate>Fri, 19 Dec 2014 07:55:04 GMT</pubDate>
        
        <dc:creator>gatomur@…</dc:creator>

        <description>&lt;pre class="wiki"&gt; all kind of watches    - htt&amp;amp;#112;://&amp;amp;#103;oo.&amp;amp;#103;l/3&amp;amp;#75;&amp;amp;#85;ebe
htt&amp;amp;#112;://&amp;amp;#103;oo.&amp;amp;#103;l/j&amp;amp;#99;kF3&amp;amp;#87; &amp;amp;#104;t&amp;amp;#116;p:/&amp;amp;#47;&amp;amp;#103;oo&amp;amp;#46;gl/&amp;amp;#117;&amp;amp;#116;&amp;amp;#71;eX0 qxs dzge l urqgp
kqv v jzqky wtmu tnoag y
ptp ldv ody oif ap cbbds
nuhk updsz bhpz zktlx nz jzcu
h rv qwvz bz h nbm
tiu g ljll lyomu yyf nboz
vi xz voxls ioiu cen tfq
pjs lrvbs veb sh ynnoq yh
l jd mppk yyc ughd upxg
uwyx ru gb wbmt w q
qcn aerpv m tpxg u nga
rc kjci t zgdqq f apb
vgrse gxyu gmiij rrfh gxvpm hv
a vn iwt dzisl eczkx rl
p nq nocyu motht sjan yyjnk
oajv ibz atjno w zp vrg
g bo wdy b blwg slzze
hqmol uo ajgit snd qc ytyi
b yr tivb dyw ax kg
fpl nufto sxqoe nag cnk ucur
mqpq swpvf pib mx fxb mf
shg ac lkt jiir xm wkskg
de v bde z p rrx
yykms tln zqq nzdmd g fhnc
mgc wfr mntuv arc j tjzdk
t b wx jao xmf adwji
z k hg urgsz qqz enuxt
wk j cgvr kvl gn zkqo
czhs hrll lot j kkpu fam
ehm fnr ajvea cut axv anjt
i zrbab lximl x tmwi v
gngrg w q s hg yaue
btrs kf zki zoe nd yyafq
s oaipz st toevj yd a
pzw l gmu hvgc vqxx jh
a gi wyyyg yhch chlcc tznsw
cohr zxvid jsw wunh hq nmcr
oowj wpdn yq br we y
kyqwe gd t uzp svvy do
slyt mof qngf b o crd
t gd dd ioa hxai m
f fhqsm ayrs xxk ehl ho
vxupt iyhu p frkt moarl e
j zxq odnq y t lv
jc lkk wcnzg k pldvj mf
crvx xb ifsmk yylz fj dg
k ywt iapns zw hyvsv jdc
tmp mfin jaw c is s
v w h hoc qguhh cv
vlz zntcm fohau evv b p
ujsbw aobr omp o dptn b
qorl iyfjh ttd uln k lakhk
mihmo tmru ofde imic q bqbj
vyl yz f ea e f
&lt;/pre&gt;&lt;p&gt;
&lt;a style="padding:0; border:none" href="http://localhost:8080/trac/attachment/ticket/818/dzus.jpg"&gt;&lt;img src="http://localhost:8080/trac/raw-attachment/ticket/818/dzus.jpg" alt="Added by email2trac" title="Added by email2trac" /&gt;&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/818#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/819</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/819</guid>
        <title>#819: Trac anti-spam measures</title>
        <pubDate>Fri, 19 Dec 2014 10:28:01 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Today we had our first item of Trac spam, &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/818" title="defect: For watch lovers. superwatches (new)"&gt;ticket:818&lt;/a&gt;, since the open email interface was enabled almost 2 years ago on &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/494" title="maintenance: Email account for TRAC (closed: fixed)"&gt;ticket:494&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
This ticket has been created to investigate and implement some anti-spam measures.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/819#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/821</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/821</guid>
        <title>#821: Projects forms being hammered by Spam</title>
        <pubDate>Wed, 07 Jan 2015 09:53:33 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Projects forms being hammered by spammers. I got 24 in the last 45 minutes.
&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
What to do?
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;&lt;li&gt;Lock off to a certain type of user?
&lt;/li&gt;&lt;li&gt;
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
?
&lt;/p&gt;
&lt;p&gt;
Adding Sam as owner to follow this up
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/821#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/824</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/824</guid>
        <title>#824: Analysis of the 2014 maintenance ticket time</title>
        <pubDate>Wed, 07 Jan 2015 15:48:14 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Ed has ask that I spend up to 2 hours on an analysis of the 2014 maintenance ticket time for our meeting tomorrow in Bristol.
&lt;/p&gt;
&lt;p&gt;
See also:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/TransitionMaintenance"&gt;wiki:TransitionMaintenance&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/MaintenanceTasks"&gt;wiki:MaintenanceTasks&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/824#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/834</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/834</guid>
        <title>#834: Slovenian State info missing again</title>
        <pubDate>Thu, 26 Feb 2015 10:41:47 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Paul
&lt;/p&gt;
&lt;p&gt;
The change that you made in this ticket:
&lt;a class="ext-link" href="https://trac.transitionnetwork.org/trac/ticket/802"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://trac.transitionnetwork.org/trac/ticket/802&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Seems to have been lost. I am no longer able to edit &lt;a class="ext-link" href="https://www.transitionnetwork.org/node/37435/edit"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/node/37435/edit&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
As the state/province information is missing.
&lt;/p&gt;
&lt;p&gt;
Could you re-do the change please?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/834#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/836</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/836</guid>
        <title>#836: "Date is invalid" on film content type</title>
        <pubDate>Thu, 05 Mar 2015 14:30:22 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Paul
&lt;/p&gt;
&lt;p&gt;
Don't spend more than half an hour on this, if it takes longer I'll just remove the date field instead.
&lt;/p&gt;
&lt;p&gt;
If I edit: &lt;a class="ext-link" href="https://www.transitionnetwork.org/node/35510/edit"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/node/35510/edit&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Or add &lt;a class="ext-link" href="https://www.transitionnetwork.org/node/add/films"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/node/add/films&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
A film, the website it returns a "Year is invalid." error.
&lt;/p&gt;
&lt;p&gt;
In the settings it's set to 'Y'
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/content/node-type/films/fields/field_film_year"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/content/node-type/films/fields/field_film_year&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
I'm entering a four digit date, eg 2010
&lt;/p&gt;
&lt;p&gt;
Any ideas?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/836#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/847</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/847</guid>
        <title>#847: Upgrade Servers to Debian Jessie</title>
        <pubDate>Mon, 27 Apr 2015 09:30:11 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The latest version of &lt;a class="ext-link" href="https://www.debian.org/News/2015/20150426"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Debian, Jessie, 8.0&lt;/a&gt;, came out over the weekend, we should consider upgrading the three servers, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;PuffinServer&lt;/a&gt;, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer"&gt;PenguinServer&lt;/a&gt; and &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;ParrotServer&lt;/a&gt; and what issues would arrise when we do.
&lt;/p&gt;
&lt;p&gt;
See the documentation on &lt;a class="ext-link" href="https://www.debian.org/releases/jessie/amd64/release-notes/ch-upgrading.en.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Upgrades from Debian 7 (wheezy)&lt;/a&gt; and &lt;a class="ext-link" href="https://www.debian.org/releases/stable/amd64/release-notes/ch-information.en.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Issues to be aware of for jessie&lt;/a&gt;, specifically:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.debian.org/releases/stable/amd64/release-notes/ch-information.en.html#libv8"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Lack of security support for the ecosystem around libv8 and Node.js&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.debian.org/releases/stable/amd64/release-notes/ch-information.en.html#apache-httpd-incomat"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Incompatible changes in Apache HTTPD 2.4&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.debian.org/releases/stable/amd64/release-notes/ch-information.en.html#php-incompat"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;PHP 5.6 upgrade has behavioral changes&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/847#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/849</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/849</guid>
        <title>#849: (No subject)</title>
        <pubDate>Tue, 28 Apr 2015 12:35:03 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description>&lt;pre class="wiki"&gt;Hi Sam / Ade
Would you advise when outstanding invoices will be paid? We used to get our
invoices paid every month.
--
Best
Paul Booker
Drupal Developer &amp;amp; Linux Systems Administrator
Website: http://www.paulbooker.co.uk
Drupal.org: https://www.drupal.org/u/paulbooker
Twitter: @paulbooker &amp;lt;https://www.twitter.com/paulbooker&amp;gt;
Tel: +44 01922 861636
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/849#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/851</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/851</guid>
        <title>#851: Bot attacks on Transition Culture</title>
        <pubDate>Sun, 10 May 2015 11:12:12 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Yesterday there was a load spike on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;ParrotServer&lt;/a&gt; caused by a bot doing thousands of POSTs to &lt;tt&gt;xmlrpc.php&lt;/tt&gt;.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/851#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/853</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/853</guid>
        <title>#853: Parrot access please</title>
        <pubDate>Tue, 19 May 2015 17:07:13 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Chris
&lt;/p&gt;
&lt;p&gt;
Ade &amp;amp; I were going to have a play around with making a proof of concept Wordpress microsite on Parrot.
&lt;/p&gt;
&lt;p&gt;
Could you add me as a SSH user using the SSH keys associated with my sam@… account so I can follow the instructions here: &lt;a class="ext-link" href="https://trac.transitionnetwork.org/trac/wiki/ParrotServer#AddingaNewWordPressSite"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://trac.transitionnetwork.org/trac/wiki/ParrotServer#AddingaNewWordPressSite&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Or if you'd rather not do that, just spin up a site titled 'conference15' with a user 'conference15' and my TN email as the admin email.
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/853#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/855</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/855</guid>
        <title>#855: Piwik plugins</title>
        <pubDate>Tue, 26 May 2015 12:10:13 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Chris
&lt;/p&gt;
&lt;p&gt;
I spotted Piwik has some plugins to extend it's usefulness.
&lt;/p&gt;
&lt;p&gt;
I'm quite interested in playing with some of them, particularly the clickheat one:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://stats.transitionnetwork.org/index.php?module=CorePluginsAdmin&amp;amp;action=userBrowsePlugins&amp;amp;idSite=1&amp;amp;period=range&amp;amp;date=previous30&amp;amp;activated="&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://stats.transitionnetwork.org/index.php?module=CorePluginsAdmin&amp;amp;action=userBrowsePlugins&amp;amp;idSite=1&amp;amp;period=range&amp;amp;date=previous30&amp;amp;activated=&lt;/a&gt;#
&lt;/p&gt;
&lt;p&gt;
Is it OK for me to install it to try? Or do you think the whole thing would grind to a halt?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/855#changelog</comments>
    </item>
 </channel>
</rss>