Categories
UT Drupal Kit

UT Drupal Kit 2.13.3 Security Release – Media Module

ITS has posted a second patch-level release of the UT Drupal Kit today in order to address a critical security vulnerability in the Media module announced on April 25, 2018 (View the complete security advisory on Drupal.org).

It is recommended that all users of the UT Drupal Kit update their sites with this latest version as soon as possible.

We apologize for putting site owners in the position of having to upgrade sites twice in rapid succession, but the security advisory for the Media module was not released until almost two hours after the Drupal core update, and we had already completed the packaging and release process for the Kit by that time.

The Drupal security team is advising that all sites upgrade to this latest version of the Media module as soon as possible, so we have prepared this second release out of an abundance of caution.

How to Update the UT Drupal Kit

Complete instructions for updating a UT Drupal Kit site are available on the documentation wiki.

Please review the release notes thoroughly, and always make backups of your code, files, and database before proceeding with an update!

Categories
UT Drupal Kit

UT Drupal Kit 2.13.1 Security Release

ITS has posted a patch-level release of the UT Drupal Kit in order to address the critical security vulnerability in Drupal core announced on April 25, 2018 (View the complete security advisory on Drupal.org).

It is recommended that all users of the UT Drupal Kit update their sites with this latest version as soon as possible.

How to Update the UT Drupal Kit

Complete instructions for updating a UT Drupal Kit site are available on the documentation wiki.

Please review the release notes thoroughly, and always make backups of your code, files, and database before proceeding with an update!

Categories
UT Drupal Kit

UT Drupal Kit 2.13 Release

ITS is happy to announce the immediate availability of UT Drupal Kit 2.13, the (lucky) thirteenth maintenance release for our University distribution since the inclusion of the Forty Acres theme and the Page Builder module.

The 2.13 release includes a fix to the appearance and behavior of menu items in the main navigation of the Forty Acres theme, as well as a new contrib module that improves accessibility for embedded iframe content. There are a number of contrib module updates, and this release also includes Drupal Core 7.58, which incorporates a critical security update previously released in version 2.12.3.

MENU BEHAVIOR FIX

The 2.13 version of the Forty Acres theme fixes a bug in the main menu display that occurs with second-level menu items that are long enough to break onto multiple lines. As a result of these changes, the width of the menu dropdowns now varies consistently based on the number of items in the menu, which determines how many columns will be used to display the items.

NEW CONTRIB MODULE – IFRAME TITLE FILTER

The 2.13 release includes a new module that was created by the ITS Drupal team but is maintained on Drupal.org — iFrame Title Filter. The objective of this module is to increase compliance with WCAG 2.0 AA accessibility guidelines by providing a title attribute for all iframe elements present on a page, even if the title was not provided by the provider of the iframe’s original source.

This module will be enabled by default as part of the “Filtered HTML” text format on all sites installed on version 2.13 or later. Sites installed prior to version 2.13 can add this functionality by enabling the iFrame Title Filter module and enabling it in the desired text format(s).

CONTRIB UPDATES

The 2.13 release includes updates to the following contrib modules:

HOW TO UPDATE THE UT DRUPAL KIT

Complete instructions and download links for updating a UT Drupal Kit site are available on the documentation wiki. Pantheon site dashboards that use the UT Drupal Kit distribution should see the upstream updates available now; see the Pantheon documentation for more information on applying upstream updates.

Please review the changelog and special release notes thoroughly, and always make backups of your code, files, and database before proceeding with an update!

NEXT RELEASES

The UT Drupal Kit is released on bi-monthly maintenance release schedule, with releases targeted for the second Tuesday of the month. The next planned release for this year is UT Drupal Kit 7.x-2.14, due on June 12, 2018.

If you have questions or concerns about the UT Drupal Kit, please feel free to email us at drupal-kit-support@utlists.utexas.edu.

Categories
UT Drupal Kit

UT Drupal Kit 2.12.3 Security Release

ITS has posted a patch-level release of the UT Drupal Kit in order to address the highly critical security vulnerability in Drupal core announced on March 28, 2018 (View the complete security advisory on Drupal.org).

It is recommended that all users of the UT Drupal Kit update their sites with this latest version as soon as possible.

How to Update the UT Drupal Kit

Complete instructions for updating a UT Drupal Kit site are available on the documentation wiki.

Please review the release notes thoroughly, and always make backups of your code, files, and database before proceeding with an update!

Categories
UT Drupal Kit

UT Drupal Kit 2.9 Release

ITS is happy to announce the immediate availability of UT Drupal Kit 2.9, the ninth maintenance release for our University distribution since the inclusion of the Forty Acres theme and the Page Builder module.

The 2.9 release includes a new Drupal core release and updates to several contrib modules, the ability to include site-specific settings via an include file, and miscellaneous small improvements and bug fixes.

DRUPAL 7.56 AND CONTRIB UPDATES

UT Drupal Kit 2.9 includes the version 7.56 of Drupal Core, which is a security release that addresses a moderately critical issue related to anonymous file uploads into the private file system. Please review the release notes before updating to check for any issues that may affect your site.

This release also includes updated versions of the following contributed modules:

  • Caption Filter
  • IMCE
  • Media
  • Memcache
  • Panels
  • Rules
  • Video Filter
  • Views
  • Views Bulk Operations
  • Workbench Access

Of these modules, only Media, Views, and Video Filter are enabled by default in the UT Drupal Kit.

Several of these updates require database updates, so be sure to run available updates via https://example.com/update.php or drush updb after upgrading your site’s codebase.

Two of these contrib module updates merit special attention:

  • The Media module update addresses a previously identified issue related to apply links on images inserted via the Media button in the WYSIWYG editor. This new Media release does now allow linking Media-inserted images, but enabling this capability requires making a change to your text format settings. Please see the 2.9 Release Notes article on our documentation wiki for details.
  • The Views module update to version 7.x-3.16 is described by the Views maintainers as a “rather major bug release,” so should be tested thoroughly for regressions, particularly related to CSS class names. Please review the module release notes for details.

ALLOWING FOR SITE-SPECIFIC SETTINGS FILE

Site owners wishing to use Drupal’s settings.php file for their own purposes–such as hard-coding site settings via the $conf array, or for implementing environment detection logic for environment-specific setting overrrides–have been challenged by the fact that we include a settings.php file in the UT Drupal Kit distribution. For Pantheon site owners, this means manual resolution of a git merge conflict for every upstream update. For non-Pantheon site owners, it means that updates to the Drupal Kit’s settings.php file must be manually merged into their own settings.php file.

To improve developers’ experience regarding this issue, there is now a conditional include at the bottom of the default UTDK sites/default/settings.php file that will load a file called site-settings.php if it is found in the same directory. This can be used for implementing site-specific settings changes such as exposing additional block types to the Page Builder layout editor, or overriding which types of social media accounts are available in the Social Media Links field or the sitewide Social Media accounts configuration.

There is an example file located at sites/default/example.site-settings.php which can be copied/renamed to sites/default/site-settings.php, and includes commented-out examples of the previously described configuration customizations.

Please note that the previously-existing include for local-settings.php is still in place, and comes after site-settings.php, meaning that settings from local-settings.php will still continue to override all other settings.

MISCELLANEOUS IMPROVEMENTS

  • A change to the Forty Acres theme’s CSS improves the color-contrast ratio of the text and background colors of the UT Drupal Kit’s mobile menu display.
  • Fields with no data will no longer display as available to be placed via the Layout Editor provided by the Page Builder module.
  • The placement of the Google Tag Manager snippet has been moved in order to comply with Google’s best practice recommendation that the <script> element be located inside the <head> element and that the <noscript> element be located immediately following the opening <body> tag.
    • Please note that this change means that the Google Tag Manager module can no longer track pageviews in the Seven administrative theme. If tracking of administrative pageviews is required, site owners should use a custom admin theme.
  • The Page Builder “Resource” field would not allow entry of resource links without a headline field, but the headline field was not marked as required. This has been resolved by allowing the entry of resource links only, without an accompanying headline.
  • Custom blocks placed in the sidebar region of Page Builder templates are now styled more consistently with other field blocks placed in the same region.

BUG FIXES

  • Fixed an issue in which the “Featured Events” block would not display a solid background color when placed in a region with a background accent.
  • Fixed an issue in which custom content types containing a non-alphanumeric character would not display fields correctly in the layout editor.

HOW TO UPDATE THE UT DRUPAL KIT

Complete instructions and download links for updating a UT Drupal Kit site are available on the documentation wiki. Pantheon site dashboards that use the UT Drupal Kit distribution should see the upstream updates available now; see the Pantheon documentation for more information on applying upstream updates.

Please review the changelog and special release notes thoroughly, and always make backups of your code, files, and database before proceeding with an update!

NEXT RELEASES

The UT Drupal Kit is released on bi-monthly maintenance release schedule, with releases targeted for the second Tuesday of the month. The planned schedule for the remainder of the 2017 calendar year is:

  • October 10, 2017 – UT Drupal Kit 7.x-2.10
  • December 12, 2017 – UT Drupal Kit 7.x-2.11

Any adjustments to this schedule will be announced on this blog and on the UT Drupal users mailing list.

If you have questions or concerns about the UT Drupal Kit, please feel free to email us at drupal-kit-support@utlists.utexas.edu.