Developing (v7+)

Need Help

I have just made some changes with Html blocks on the home page of my site such as rounding corners and gradient with -web-kit and Microsoft.gradient type of codes and add some Jquery scripts. They all worked really well, however 5 minutes later, I am aut…

Navigation issues

This should be easy to answer, but I can't find it myself. Thanks in advance to those who answer: I want to use a non-autonav navigation. In other words, I have a nice (valid) html/css menu that I'm not interested in having changed automatically by aut…

Sort page list by last edited

Is there a way to have a page list display the pages in order of when they were last updated/edited? I want to use it in a portfolio section where it will show the latest, or most recently updated, client.

A larger Avatar

Is there any way to make the small Avatar photo/picture (80x80) for profiles allow larger images? I think it involves setting a global variable, maybe AVATAR_WIDTH, but am not sure how. Thanks!

Simple sidebar block

Hi - I would like to have a simple block in the sidebar that allowed for uploading an image of certain width 400px and then a title and some copy underneath. It would act as a link to areas within a site.... Is there a good starting template that I can…

3rd Party Authentication For Privileged Content

Hello Concrete5 Community, I have a client that needs to integrate association management software called Avectra with a CMS platform to serve member-only content. I love the Concrete5 platform, and I would like to push this in our primary proposal. …

XSS in guestbook form

If i post the following code (ignore the php open/close):[code]>">[/code]In the 'name' or 'email' fields, there is a disastrous XSS vulnerability. Try it, it's a safe demo. I 'fixed' it by adding some strip_tags() in concrete/blocks/guestbook/controlle…

addHeaderItem()

Is there a way such as using addHeaderItem() to add a php include statement to the header dynamically rather than adding the include directly into the template header. I want the inclusion to be dynamic and not static. basically... should this work..?…

Open Redirect Bug

Hi all There's an issue with the login that enables a malicious user to prefill the form with an rcID which can be any url. I would suggest removing the url-specified redirect and using a collectionID ONLY.

Status in the usersfriends table

Hello, I want build a block to show personal information to some of the users friends (not all). I want the user give the possibility to classify his friends. When I look in the mysql database there is a status record in the usersfriends table. …

Filter Posts