News

Aug 9, 2018

samdark

Getting information from the current locale

A wiki article about getting various information from current locale.

Jul 28, 2018

mtangoo

YiiGist - Directory of Packages for your project

Yiigist is a directory of Packages for your projects on Yii framework. It helps you find package you want and provide sorting by different criteria as well as filtering by framework version. Great tool for searching libraries before you roll yours!

Check it out!

Jul 8, 2018

samdark

Luke Briner's channel Yii 2.0 Part 19 - REST APIs

Latest video in Yii 2.0 series by Luke Briner is about rapidly building REST APIs.

Jul 6, 2018

samdark

Yii 1.1.20 is released

Yii team tagged new version of Yii 1.1 that accumulates security and PHP 7 compatibiltiy fixes made for a year.

Jun 29, 2018

samdark

Yii development notes #23

Another issue of Yii development notes by Alexander Makarov. Have a good read.

Jun 24, 2018

greeflas

Email templates module 4.1.0 released

The extension is for creating email templates and managing them in a website dashboard. You can create email templates with CRUD module in your backend or Gii generator.

Version 4.1.0 chages are:

  • Added default value for "hint" field in Gii generator
  • Added batch insert command for each language in migration file that Gii generator creates
  • Other minor improvements and fixes

All changes are avaliable in changelog file.

May 23, 2018

samdark

Queue extension 2.1.0 released

Yii team released minor version of Queue extension. It adds Amazon SQS queue support and a handy cli\Queue:EVENT_WORKER_LOOP event.

May 22, 2018

nadar

LUYA Admin module 1.2 release

LUYA Admin module release 1.2 and CMS module release 1.0.4

Admin Security Improvements

Security is a top priority for any web framework and web application, therefore it was also a very important aspect in the development of LUYA from day one. The Yii framework provides a good foundation with its security features, but every line of code built on top of it has to be as bulletproof as its foundation. When there was an opportunity to have LUYA tested with a security audit executed by a Swiss security company, we gladly took the chance. This resulted in a list of security improvements included in this update:

  • Unparsable JSON Cruft: all JSON responses are now prepended with an unparsable cruft )]}', in order to prevent "JSON hijacking".
  • The Angular source code is now uglified and minified. Therefore Angular strict-di mode is enabled by default.
  • If a user changes the account's email in the admin, we now provide the option to send a security code to the old email address which has to be entered to authorize the change.
  • The admin login security token now has an expiration time that can be configured.
  • Login attempts are now tracked by the session (session based attemption limit). If the user email is correct, another limit for user identifed login is available. After five attempts, a lockout for one hour is enabled by default. The max number of attempts can be configured.
  • The maximum idle time of admin users can now be configured.

There is also a new LUYA security best practice guide.

Admin General Improvments

  • NgRest attributes can now be displayed based on conditions. Assuming you have a select with categories, this allows you to display a certain field only when a specific category is selected. Read more
  • The filemanager provides the option to switch between inline or download for file delivery. The renaming of files is now possible, too. We also made some improvements with the display of file details, including a fullscreen preview.
  • The storage system is now completely swapable: this makes using Amazon S3 possible and available as a feature LUYA aws extension
  • The speed of the storage system was improved: we have significantly reduced the time it takes the admin to load the list of all files and images.
  • The general PHP docs were improved and deprecated methods were removed, see upgrade.md
  • The Roboto font used in the admin now supports (+Extended), Cyrillic (+Extended), Greek (+Extended), Vietnamese.

You can download and install LUYA admin version 1.2 (~1.2.0 in composer). Make sure to run the migrate command afterwards as the update includes database migrations. See the full changelog und upgrade document.

CMS

Along with the Admin module we also released CMS module version 1.0.4, which includes:

  • Minification and uglification of Angular code.
  • New command to cleanup the cms, remove deleted pages, blocks and log files: cms/page/cleanup.
  • New property to provide import paths for blocks: luya\cms\frontend\Module::$blocks.
  • New commands to list blocks and migrate them from the console: cms/block/find and cms/block/migrate. The migrate command is helpful when you want to delete an old block but assign its contents to a new block.

22 May 2018, LUYA developer team

May 1, 2018

samdark

Yii development notes #22

Another issue of Yii development notes was posted giving overview of what happened last months.

Apr 24, 2018

samdark

Smarty and Swiftmailer official extensions released

Yii team tagged two releases:

Both are fixing bugs. Smarty has an enhancement on board as well. Both are safe to upgrade via Composer.