Mahara 1.3.3

Milestone information

Richard Mansfield
Release registered:
No. Drivers cannot target bugs and blueprints to this milestone.  

Download RDF metadata


Assigned to you:
No blueprints or bugs assigned to you.
9 Richard Mansfield
No blueprints are targeted to this milestone.
9 Fix Released

Download files for this release

After you've downloaded a file, you can verify its authenticity using its MD5 sum or signature. (How do I verify a download?)

File Description Downloads
download icon mahara-1.3.3.tar.bz2 (md5, sig) release tarball 1,953
last downloaded 5 days ago
download icon mahara-1.3.3.tar.gz (md5, sig) release tarball 1,665
last downloaded 3 days ago
download icon (md5, sig) release tarball 6,706
last downloaded 3 days ago
Total downloads: 10,324

Release notes 

Mahara 1.3.3 Release Notes

This is a security release of Mahara 1.3. Stable releases are fit for
general use. If you find a bug, please report it to the tracker:

This release includes an upgrade path from 1.0. If you wish to
upgrade, we encourage you to make a copy of your website and test the
upgrade on it first, to minimise the effect of any potential
unforeseen problems.

Changes from 1.3.2:

 * Fix for XSS vulnerability (CVE-2010-3871)
 * Fixes to category namespaces and encoding in Leap2a import/export
 * Updates to selenium tests
 * Fixes to permissions in secret URL views and feedback attachments
 * Fixes in view creation wizard, embedded media block, js calendar


View the full changelog

Fix link above video in internalmedia block (bug #670266)
Fix back link from view page during view creation (bug #667879)
Enable auto_escape in groupviews block (bug #669307)
Fix bug in 'delete all notifications' for notifications with replies (bug #664521)
Fix safe_require to work with suhoshin (freebsd) realpath (bug #667051)
Fixed encoding issue in LEAP2A export: Accented characters in views were garbled in the export.
Fix timing problems in Resume tests
Define default first day of week to fix calendar for some languages (bug #663056)
Update selenium tests
Leap2: Fixed category namespace in import as well as export
Fix first access of secret url view (bug #661613)
Allow users to view files attached to feedback they can see (bug #663545)
Fix mp3 player for IE7 (bug #663594)
Fix calendar display in German (bug #663056)
leap2a: added trailing / on the end of categories namespace in xml header

0 blueprints and 9 bugs targeted

Bug report Importance Assignee Status
669307 #669307 User content not escaped in groupviews blocktype 3 High Richard Mansfield  10 Fix Released
661613 #661613 Secret URL switches to login screen 4 Medium Richard Mansfield  10 Fix Released
663056 #663056 Calendar not displaying correctly in German langpack 4 Medium Richard Mansfield  10 Fix Released
663545 #663545 Files attached to public feedback should inherit the view's access permissions 4 Medium Richard Mansfield  10 Fix Released
663594 #663594 Media player broken for MP3s and IE7 4 Medium Richard Mansfield  10 Fix Released
664521 #664521 delete all notifications 4 Medium Richard Mansfield  10 Fix Released
667051 #667051 safe_require throws exceptions for missing files when nonfatal set to true 4 Medium Richard Mansfield  10 Fix Released
667879 #667879 View creation 'Display my view' breaks step-by-step process 5 Low Richard Mansfield  10 Fix Released
670266 #670266 video link broken 1 Undecided Richard Mansfield  10 Fix Released
This milestone contains Public information
Everyone can see this information.