WackoWiki: Todo List

https://wackowiki.org/doc     Version: 14.08.2017 11:58
pls. see bugtracker[link1]

Process and release
  • committer acceptance guidelines
  • code contribution guidelines

Please help out where you can.

1. R 5.5

dev repo [bitbucket.org][link12]
Team Sessions[link14]

Main Focus: basic HTML5 support, address security related features

  1. HTTP Strict Transport Security (HSTS)
  2. Content-Security-Policy 2
  3. Cookies, CSRF sectoken
  4. https://www.owasp.org/index.ph[..]tication_Cheat_Sheet[link15]
  5. SameSite Cookie attribute[link16] https://caniuse.com/#feat=same-site-cookie-attribute


  1. Strict-Transport-Security HTTP Response Header
    • Instructs the browser to always request a domain using the HTTPS protocol instead of HTTP.
  2. Content-Security-Policy (CSP)
    • HTTP Response header, allows server to control how resources are loaded.

1.1. Security Headers

  1. foster http_security_headers() implementation
    1. https://www.owasp.org/index.ph[..]_useful_HTTP_headers[link18]
    2. https://www.owasp.org/index.php/Content_Security_Policy
    3. http://www.w3.org/TR/CSP2/
    4. https://developer.mozilla.org/[..]ders/Referrer-Policy[link19]
    5. https://w3c.github.io/webappsec-csp/
  2. abandon vendor prefixes -> Content-Security-Policy (Suggestion: avoid prefixed implementations)
    1. Content-Security-Policy:
       default-src 'self';
       script-src 'self' 'unsafe-eval' ajax.googleapis.com google-analytics.com;
       style-src 'self' ajax.googleapis.com;
       connect-src 'self' https://api.myapp.com realtime.myapp.com:8080;
       media-src 'self' youtube.com;
       object-src 'self' youtube.com;
       child-src 'self' youtube.com embed.ly
    2. Content-Security-Policy:
       default-src 'self';
       script-src 'self' 'unsafe-inline';
       style-src 'self' 'unsafe-inline';
       img-src *;
      • replace inline scripts
      • disallow scripts without nonce
  3. add nosniff header

1.1.1. Replace inline JavaScript

see JavaScript[link20]

1.2. SafeHTML / HTMLPurifier

  1. implement optional support for HTMLPurifier
    1. http://htmlpurifier.org/download
    2. http://repo.or.cz/htmlpurifier.git/shortlog/
  2. http://www.bioinformatics.org/[..]_utilities/htmLawed/[link21]

1.3. HTML5 Migration

  1. update form attributes https://www.w3.org/TR/html5/se[..]ml#the-input-element[link22]
    1. autofocus

1.4. HTTP/2

HTTP/2 RFC7540[link23]

1.4.1. Server Push

header("Link: </css/styles.css>; rel=preload; as=style, </js/scripts.js>; rel=preload; as=script");


1.5. PHP

1.5.1. PHP 7.3

  1. https://secure.php.net/manual/en/migration73.php

1.5.2. PHP 7.2

  1. https://secure.php.net/manual/en/migration72.php
    • Deprecated: Function create_function() is deprecated in /wacko/admin/admin.php on line 204

1.5.3. PHP 7.1

  1. https://secure.php.net/manual/en/migration71.php
    • Deprecated: Function mcrypt_create_iv() is deprecated in /wacko/class/ut.php on line 405
    • Warning: Cannot assign an empty string to a string offset

1.6. MariaDB / MySQL type casting


whOOt https://dev.mysql.com/doc/refm[..]ent-programming.html[link29]

1.7. Features

  1. normalize links to other language versions of a page
    • add table: lang_link[page_id, lang, target_id]
  2. add debug option to send error log into separate file + rotate logs
  3. add IP block to ban bad actors, bots
  4. add timing method to prevent more bots from creating new accounts

1.8. RC3

open issues (add)

  1. wacko.all.php ($wacko_all_resource[]) is not available, when page_lang != user_lang, why?
    • related issue: added LicenseIds[] to wacko.all.php, guess what...
  2. add delimiter before page handler (_properties)
    1. min_href()
    2. router.conf
    3. abandon standard_handlers (?)
  3. Guide to build templates[link9]
  4. Permalink to page vs page version
  5. CSS does not get routed in RECOVERY_MODE
  6. save failed $_POST data[link30] for reuse after forced logout or autologin
  7. route TLS-Proxy – not part of page name space
  8. recognize audio and video files and use new html5 tags <audio> <video> using the link function
  9. relative time
    1. global / user setting
    2. where to use relative time and where not 
    3. different schemes
  10. invalidate SQL and page cache (with common function) (?), which is also checking against config settings
  11. add also footer after hard return, GUI consistency
  12. how to check access privileges for a group, e.g. has_access() for $ -> moderate handler : locking
  13. upload of file without extension -> broken
  14. allow only common reasonable extensions for upload
    1. blacklist MIME types -> implement
    2. blacklist extension -> update
    3. white list
  15. add notification for 
    1. new page -> Admin, Moderator, parent page owner
    2. new attachments
      1. -> to page: watchers, Admin, Moderator
      2. -> global: Admin, Moderator
  16. add default max value in actions: news, blog, files, etc. -> use list_count as default
  17. empty body_r after page rename/relocation -> page needs rerendering
  18. installer: rewrite_mode option ! – dysfunctional
  19. https://wackowiki.org/doc/Bugs%2FWackoWikiStart ->
    Not Found
    The requested URL /doc/Bugs/WackoWikiStart was not found on this server.
  20. redirect hashid url?
  21. double click in edit / write comment form field should not load edit page, user looses his already written content, ANNOYING
    1. additional user should get a warning like it is done for page edit: Do you really want leave .., you will lose your content
  22. delete / reset pages with missing language, e.g. 'mo', upgrade or AP routine
  23. allow multi logins (on/off)
    1. add multi login warning: 'Jemand hat sich bereits an diesem Konto angemeldet'
    2. This account is currently being used in 1 other location at this IP ().
  24. add access throttling feature
    • limit the number of page requests by a single IP address within a given time interval
  25. revisions.xml handler adds falsely,
    1. </body></html>
    2. <!-- WackoWiki Caching Engine: page cached at 2017-05-21 07:41:20 -->
    3. and diag output
    4. see final.php
  26. load translation is loaded before resource for theme lang is set for theme_per_page, FIXED same issue for user theme
  27. add array for 'default' AND 'user' menu so both can used independently (create/edit menu sets)
  28. common header can't be reused for none template themes -> fix?
  29. rewrite_mode setting in AP is pointless if it is overwritten in Setting class
  30. wacko.all.php settings in themes were ignored! Fix?
    •  <?php
      // tabs theme options =========
      	$this->db->revisions_hide_cancel = 1;
      	$this->db->footer_inside = 0;
      // ============================
      $theme_translation = [
      	'EditIcon' => '<img src="' . $this->db->theme_url . 'icon/edit.png" alt="Edit included page" />',
      	'' => '',

1.9. Fix

  1. invalidate / purge only a sub set of the SQL cache (?), do we always need to purge the entire cache?
  2. check formatting of log() function -> html / wacko formatting
  3. use common list count setting per user + use it as default in lists for paging
  4. check for avoidable SQL roundtrip queries
    1. e.g. translit: href() -> mini_href() -> slim_url() -> translit() ($this->config['multilanguage'] == true) -> load_page()
    2. fix additional round trips gaining page_id in combination with has_access() and link() function (tag <-> page_id)
      1. options: use object cache or pass variable page_id via link() function:
        • // cache page_id for for has_access validation in link function
        • $this->page_id_cache[$page['tag']] = $page['page_id'];
      2. part 1: revision:f5f2295a85b9[link31]
    3. add object for extending and array with default pages (accessible via theme) to preload_link() function
      1. -> ensure pre caching to avoid single lookup per intralink in DB on each page call
      2. -> parse also page path for bread crumbs in page_link table
  5. link() -> default: $anchor_link – should only active inside page_body (?)
    • additional check if its better to prefix the id="doc.deutsch.konfiguration"
      • to avoid unintentional mix with CSS settings
    • set anchor id only where needed, minimizes also size of attributes
  6. add option help to action to show all parameters in a info box 
    1. echo ''
  7. <#<kbd>F1</kbd>#> – add css class for kbd tag 
  8. broken list in tree action if levels changes not in order – e.g. depth 1.2 -> depth 2.4
    1. show missing levels
  9. add function to replace random isset($_GET|$_POST) ? .. : null
    1. filter_input[link32] # gets a specific external variable by name and optionally filters it 
  10. search?phrase="sourceforge.net" -> paging fails with "term to search"
  11. bug: news action takes all subpages – is this desired?
  12. improve search[link33] (open since ages), add some measures to improve relevance (time, size, user, filter, ...) and provide more and better meta data for search results
  13. add options to show/hide page related categories at the page bottom
    • themes may overwrite these settings via $this->config['footer_tags'] = OFF
    • allways ON as default for posts in the forum cluster
    • do we need an additional option for the user?
  14. get translation
    1. put lang-strings for action and handlers into separate dynamically loadable lang-files
    2. cache
  15. audit comments, moderation handler
  16. replace p tag in toc action -> avoid wrong p in p 
  17. should we allow page names like chicken.egg, might conflict with other settings like tikiwiki formatter option
  18. review concept handling files per page file?get= -> performance, time, resources, necessity, alternatives
  19. Form in preview breaks Edit / Preview form -> produces nested form -> filter?
  20. revisit access right settings for forum posts and menu access
    1. the menu won't show the page properties icon -> annoying
  21. syntax
    1. table header
  22. implement rating hack (but without mandatory JS)
    1. https://www.youtube.com/watch?v=orPVEAipz2A
  23. add graphviz formatter[link35] to /community/formatter
  24. image action
    1. resize, cache
    2. using library
    3. store thumbnails in extra folder
      1. under files/ or _cache/ [..] thumbnails/
      2. global / per_page
  25. add unique log message key to filter events (messages may differ)
  26. use deleted field to mark deleted pages, comments, files
    • basics implemented for page and files
    • open: rollback/restore procedure and handling of final deletion
    • check how we do this for files alone and/or with related page (matrix)
    • WHERE clause from COUNT(*) queries
  27. disable global upload for users
    1. only local
    2. only for cluster
  28. add regex for this->config['users_page']/[*]/
    • Yet the engine does not validate the namespace for the user cluster, so that nobody can create a page under /User except his own [UserName]
    • Then we can disallow random pages for the first level in the users cluster except the own [UserName].
    • The register action creates this page usually for the user.

1.10. Notifications

  1. email body and subject message encoding is pure shit in multi-language mode
    1. _t() function gives back html entities
  2. Notifications[link36]

1.10.1. Notice digest

1.11. Installer

  1. installer: add missing form label fields
  2. mode_rewrite is OFF / not available
    • 'base_url' => 'https://example.com/wiki/' ?
    • https://example.com/wiki/?page=OpenTasks
  3. colliding page names with multiple languages with the same name -> insert_page()
    1. creates only the first match, other page and menu creations will fail
    2. Solution: (A) UTF-8, (B) different page names, e.g. index, index
  4. legacy upgrade: SQL strict mode and missing default values -> HOTFIX: set default values manually via phpMyAdmin
    1. see table structure and select all rows with Default -> None
    2. chose change at the bottom and change Default -> None to As defined: and save
    3. repeat this for all related tables if necessary

1.12. Handler

  1. disallow white space in tags: new and moderate -> strip
preg_replace('/\s+/', '', $string);

  1. add rel="canonical" to show handler?
  2. review transliteration of file names in upload handler: white space, '-', '_'
  3. clone entire cluster is only available foe Admins atm., it should also available for ...
  4. improve global upload settings
    1. allow groups
    2. set individual rights (only images, quota, etc. for a user, group)
  5. send page as email (like print)
  6. show: add option 'Flag as Spam/Inappropriate'
  7. diff: show time, revision, user and change note for side A and B 
  8. show: Delayed Indexing delay_index
    • <meta name=“robots” content=“noindex,nofollow” />
  9. see upload[link37] subpage
    1. upload: check if the MIME type of the uploaded file matches the file extension
      1. https://www.owasp.org/index.ph[..]stricted_File_Upload[link38]
      2. https://www.acunetix.com/websitesecurity/upload-forms-threat/
      3. https://secure.php.net/manual/[..]n.exif-read-data.php[link39]
    2. upload: add form field to chose another file name (?)
    3. upload: add accept attribute depending on config settings https://www.w3.org/TR/html5/fo[..]ml#attr-input-accept[link40]
    4. upload: send a notify mail on upload
  10. unify form label style, see filemeta, properties, account handler
    • make label secondary ->
  11. add meta handler namespace ['page', 'account', 'file', 'service']
    • This is the simplest way to standardize document locations and for the language-independent single instances of service pages, like login. Next step is the separated cluster for those pages, linked with prefix, for example, ((service:login)).
    • this can be easily done with the new URI router
    • handler/account/
  12. file: apply access restrictions for global files if Wiki is closed -> $
    1. add and enforce global Wiki mode, minimum access rights
    2. route global files only for registered users

1.13. Action

  1. template toc and tree

1.14. Formatter

  1. Search Highlighter
  2. (/Users/WikiAdmin UserSpace | WikiAdmin)) -fails on |
  3. <# #> adds <!--notypo--> on first and <!--/notypo--> on second appearance of double quote like class=""
    1. <#<div class="" style="background:transparent; border:.1em solid #F66; border-left:1em solid #F66; box-sizing:border-box; margin:.5em 0; overflow:hidden; padding:.5em; text-align:left; width:auto;">Unter den Btrfs-spezifischen Anpassungen (1, 2) waren einige, die Latenz- und Stabilitäts-Probleme beseitigen, die bei knapp werdendem Speicherplatz auftreten können.</div>#>
      <#<div class="" style="background:transparent; border:.1em solid #fcfce9; border-left:1em solid #fcfce9; box-sizing:border-box; margin:.5em 0; overflow:hidden; padding:.5em; text-align:left; width:auto;">Unter den Btrfs-spezifischen Anpassungen (1, 2) waren einige, die Latenz- und Stabilitäts-Probleme beseitigen, die bei knapp werdendem Speicherplatz auftreten können.</div>#>
    2. <!--notypo--><div class="<!--notypo--> style="background:transparent; border:.1em solid #F66; border-left:1em solid #F66; box-sizing:border-box; margin:.5em 0; overflow:hidden; padding:.5em; text-align:left; width:auto;">Unter den Btrfs-spezifischen Anpassungen (1, 2) waren einige, die Latenz- und Stabilitäts-Probleme beseitigen, die bei knapp werdendem Speicherplatz auftreten können.</div>#><br />2<br /><#<div class=<!--/notypo-->" style="background:transparent; border:.1em solid #fcfce9; border-left:1em solid #fcfce9; box-sizing:border-box; margin:.5em 0; overflow:hidden; padding:.5em; text-align:left; width:auto;">Unter den Btrfs-spezifischen Anpassungen (1, 2) waren einige, die Latenz- und Stabilitäts-Probleme beseitigen, die bei knapp werdendem Speicherplatz auftreten können.</div><!--/notypo--><br />
  4. Image links to other sites
    • The automatically added symbol for an outerlink is misplaced here, e.g.:
      • ((http://example.com/ https://www.example.com/media/img/logo.png))
      • [link41]
  5. Wacko is spamming BRs, in between everything
  6. add option to hide protected links
    • You must login to see this link. Register now, if you have no user account yet.
    • add 'nofollow' to protected link -> class="acl-denied"
  7. Wacko is putting P.auto around DIV elements = Plain Simple Bullshit -> bugs:375[link42]
    1. should not set paragraphs in cases like
    2. <p class="auto" id="p96596-1"><!--notypo--><pre class="code">
      <p class="auto" id="p21312-1"><!--notypo--><div class="layout-box">
    3. leads to invalid html tag nesting
  8. Error: Bad value 4 for attribute type on element ol.
    1. see $new_indent_type in wackoformatter -> error prone
      •   1. hallo
            5. should not take the number but 1, same for i, I, a, A
    2. Block elements inside inline elements
    3. http://www.w3.org/TR/html5/gro[..]nt.html#attr-ol-type[link43]
  9. even if wiki_links were turned off (disable_wikilinks) the formatter should try to form links for in intralinks with at least one slash (?) like
    • /Dev/Release/R50/ReleaseNotes#h1433-7
  10. place holder
    1. div.image {
      	width:            100px;
      	height:           100px;
      	background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR4nGP6zwAAAgcBApocMXEAAAAASUVORK5CYII=');
  11. allow case insensitive matching of file links, e.g. File:image.jpg
  12. breaks quote
  13. ((image.jpg)) shows images from image/ folder ???
  14. display of correct headings inside wrapper %%(wacko wrapper="shade") with toc is broken
  15. https://de.wikipedia.org/wiki/Gehörnte_Mauerbiene
  16. <[ ]> eats blank line in quote, undesired
  17. broken nested quote
    • <[block
      <[nested quote]>

1.15. Template Engine[link9]

  1. Templatest deliberately eats all line breaks
    • textarea issues <textarea>[ ' body ' ]</textarea>
      1. multi-line
      2. auto-indent
    • edit, comment, permission, caption, ...
  2. write templates.tpl for remaining actions and handlers where suitable DONE

1.16. Cache

1.17. Admin Panel

  1. add Check for Updates button in Admin panel: /Download/VersionCheck[link44]
  2. Synchronizing data: update comment count for page if out of sync
  3. Querying the RIPE Database[link45]: https://apps.db.ripe.net/db-web-ui/#/query
    1. https://rest.db.ripe.net/search.json?query-string=
    2. user approval
    3. event log 
    4. Bad Behavior
  4. upload module
      Before adding random file/MIME types: please think about possible security issues.
      For example HTML (.htm, .html), JavaScript (.js) and PHP (.php) file are types you’d better avoid as they can be “executed” on your server where you really would not want that to happen. For most of these kind of files, this should not be a problem though as these files are better off being compressed into a ZIP file anyway.
      Only add file types that you REALLY need and that you are comfortable with.
  5. user management
    • deactivate / delete inactive users
      • criteria
      • actions
  6. add module to filter, moderate and manage pages, comments, (files)
    1. see modules for content like pages
  7. recovery mode: CSS and images won't load FIXED
  8. use collgroup for col span % width
    • <colgroup>
        <col span="1" style="width: 10%;">
        <col span="1" style="width: 5%;">
        <col span="1" style="width: 5%;">
        <col span="1" style="width: 45%;">
        <col span="1" style="width: 15%;">
        <col span="1" style="width: 10%;">
        <col span="1" style="width: 10%;">
    •  <thead class="data-head">
              <tr class="">
      <tbody id="table-section-one">
      <tbody id="table-section-two">

1.18. Database

  1. https://www.digitalocean.com/c[..]ur-mysql-5-7-upgrade[link46]
  2. /Dev/Guidelines/SQL/SQLmodes[link10]

1.18.1. Check for SQL STRICT mode[link10] violations

  1. Using GROUP BY and selecting an ambiguous column
  2. Inserting the non standard zero date into a datetime column
  3. Inserting a 20 character string into a 10 character column
  4. Division by zero
  5. Inserting a negative value into an unsigned column

so far

  1. #1406 – Data too long for column 'description' at row 1
    1. set HTML maxlength="DB_FIELDSIZE" for all (VAR)CHAR form field
      • suggested (JS hint – might differ in some cases – smaller, e.g. meta description 160, meta title 60) + database field size (mandatory enforcement)
      • JS hint: You have <strong>60</strong> characters left
    2. set PHP length check before passing to INPUT / UPDATE
  2. #1055 – 'dev.g.group_name' isn't in GROUP BY

`DIGEST_TEXT` AS `query`,
`COUNT_STAR` AS `exec_count`,
`SUM_ERRORS` AS `errors`,
(ifnull((`SUM_ERRORS` / nullif(`COUNT_STAR`,0)),0) * 100) AS `error_pct`,
`SUM_WARNINGS` AS `warnings`,
(ifnull((`SUM_WARNINGS` / nullif(`COUNT_STAR`,0)),0) * 100) AS `warning_pct`,
`FIRST_SEEN` AS `first_seen`,
`LAST_SEEN` AS `last_seen`,
`DIGEST` AS `digest`
((`SUM_ERRORS` > 0) OR (`SUM_WARNINGS` > 0))

1.19. WikiEdit

  1. use only one popup for new link, having link and link description together
  2. popup for tables
3. select rows and columns
  1. set table header
  2. select color for text and highlighting
  3. undo / redo
  4. javascript search&replace
  5. symbols

1.20. Translations

-> /Dev/Release/R55/Translations[link47]


  1. "\n\n"
    "Click on the following link to view the page:\n\n"
    • function notify_watcher

Refactor message sets, e.g. use only a common set for generic messages 'CancelButton'

1.20.1. improve notifications

-> Notifications[link36]

  1. 'EmailRegistered' => 'You\'ve successfully registered at %1.'."\n".'Your username: %2'."\n\n".'If you want to receive notifications, you must click on the link below or copy it to a web browser.'."\n".'%3'."\n\n".'Please return to the Wiki and login with your new username and password.'."\n\n\n".'If you did not request any registration, ignore this message and nothing will happen.'."\n\n".'Do not reply to this message'."\n\n".'',
  2. revisit all email message sets

1.21. Usability issues

  1. indicate page [language|permissions]
  2. When should I use a select box instead of radio buttons?
    1. https://www.nngroup.com/articl[..]es-vs-radio-buttons/[link48]
  3. Not indicating an active form field
    • e.g.
      textarea:focus {
          border: 1px solid red; }
    • You can use the ‘:focus’ selector on lots of elements, but it’s super handy when used on inputs and textareas to indicate that the field is active. Add CSS styling such as a highlighted border, or a subtle change to the background color.
  4. forms with checkboxes and options in lists
    • e.g. category handler or users in admin panel
    • assignment of form buttons
  5. usage of new page handler
    • seen in many fresh installs, users adding sub pages to HomePage/subpage
      • this is possible but is it really desired and understood, should we filter out system pages as pre-provided cluster in the /new [page] handler?
  6. make name spaces for users and groups more intuitive accessible
    1. users/nickname/userspace/..
    2. groups/usability/groupspace/..
  7. add ability to easily create groups and to add group members
    1. suggestions?
  8. GUI inconsistencies
    1. handler
    2. actions
    3. message boxes
  9. Your session has timed out. Please sign in again.[link30]


  1. https://www.nngroup.com/articles/low-contrast/
  2. https://backchannel.com/how-th[..]eadable-a781ddc711b6[link49]

1.22. Libs

  1. update PHPMailer to v6.0
  2. update Hashids to v2.0

1.23. Extentions

1.24. Refactoring

  1. start replacing magic numbers at least with true and false where possible
  2. erode the mountain of technical debt
  3. https://www.owasp.org/index.php/Logging_Cheat_Sheet

1.25. Staging Area

  1. blog action (will replace news action)
  2. snippet action
  3. forum, topics action
  4. Admin Panel
    1. refactor -> antipatterns
    2. bad behaviour module
    3. list and check each module, assign status
  5. moderate handler -> quite a mess
  6. poll actions -> quite a mess

1.26. Ideas

  1. spam / badword handling -> bad_words($text) function
    1. https://en.wikipedia.org/wiki/Wordfilter
    2. https://stackoverflow.com/ques[..]ood-profanity-filter[link50]
    3. What you need is a good way for users to flag inappropriate content and a mechanism to deal with it swiftly. One way is to automatically hide/remove content if it's been flagged more than X times.
  2. HTML5 media action: {{media type="[audio|video|flash]" source=http://.... [width=000] [height=000] [...some other options...]}}
  3. rel="edit" -> https://tools.ietf.org/html/rfc686
  4. enforce ACL-Policy, e.g. set read to $, user can't overwrite the setting
  5. test PHPThumb alternatives
    1. https://github.com/mosbth/cimage
  6. Composer[link51]
  7. https://github.com/openpgpjs/openpgpjs
  8. https://highlightjs.org/
  9. https://github.com/FineUploader/react-fine-uploader as extension
  10. https://www.w3.org/TR/css3-page/
    1. https://www.smashingmagazine.c[..]-for-print-with-css/[link52]

1.27. Themes

  1. Clean up themes section[link53]
    • update repo links and info section
    • foster or (re)move theme
  2. default theme:
    1. switch from pixels to (root) ems 
    2. increase global font-size from 13px to 16px
    3. add flexbox support
  3. new mobile ready theme / layout[link54] -> on hold (we got a new template engine!)
  4. https://github.com/KDE/breeze-icons
  5. https://developers.google.com/web/fundamentals/
  6. https://www.w3.org/Style/Examples/007/leaders

Flexbox vs Grid

  1. Flexbox: content dictates layout
  2. Grid: container dictates layout (to some extent)

Flexbox is great, it just isn't the best thing for overall page layouts.
Flexbox and grid play well together, and are a huge step forward from the float & table hacks they replace. The sooner we can use them both in production, the better.

CSS Varibles

  1. https://developer.mozilla.org/[..]/Using_CSS_variables[link56]
  2. https://www.w3.org/TR/css-variables/

CSS colums for index <div class="gimme-columns"><ul>

.gimme-columns {
	columns: 20em 3;
	column-count: 3;
	column-width: 20em;

default theme

1.27.1. SVG

Icon setting: add viewBox="0 0 16 16" AND height="16" width="16"


1.27.2. Site Logo

Customizable Logo and Favicon

  1. Location
2. currently image/ folder
  1. chmod issue
  2. Options
    1. Favicon
      1. site_favicon
    2. Logo
      1. site_logo
      2. logo_width
      3. logo_height

1.27.3. Favicon

Supported Formats

  1. ico -> type="image/x-icon" ->
  2. png -> type="image/png" -> http://caniuse.com/link-icon-png
  3. gif -> type="image/gif" ->
  4. svg -> type="image/svg+xml" -> http://caniuse.com/link-icon-svg


  1. 16×16
  2. 32×32
  3. 48×48
  4. 64×64

  1. https://en.wikipedia.org/wiki/Favicon
  2. https://github.com/audreyr/favicon-cheat-sheet
  3. https://html.spec.whatwg.org/m[..]antics.html#rel-icon[link57]

1.28. Documentation

  1. add documentation for Admin Panel
    1. backup and restore module
  2. Update / foster Core Documentation for
    1. Deutsch
    2. English
    3. Français
    4. Русский
  3. describe forum and topic action
  4. blog action -> Blogging with WackoWiki
  5. where and when you should use relative or absolute addressing (include action, files, actions with page parameter)
  6. how you use the include function (pages, comments)
  7. release notes
    1. add a New & Noteworthy section / sub page to raise visibility of 'hidden' features
  8. moderate handler
  9. message functions and usage
  10. add sub page to config documentation about CSP 
  11. Video Tutorials
  12. update screen shots

1.29. Feedback

  1. themes
  2. migration and encoding issues
  3. frequent annoying issues
  4. unsolved questions
  5. add rfc section in dev cluster
  6. add dev activity log 
  7. Nginx configuration (rewrite rules)

1.30. Testing

  1. Tools
    1. https://developers.google.com/speed/pagespeed/insights/
    2. https://securityheaders.io/
    3. http://validator.w3.org/nu/
    4. https://jigsaw.w3.org/css-validator/
    5. https://validator.w3.org/feed/
    6. https://web.dev/measure
    7. WAVE – Online accessibility validator[link58]
    8. http://jshint.com/
    9. https://www.google.com/webmast[..]ols/mobile-friendly/[link59]
  2. https://github.com/mozilla/readability – test with firefox reading mode
  3. /Forum/Discussion/UserPasswordReset[link60] -> solution paths

1.30.1. Test cases

-> Test cases[link61]

1.30.2. Debug

  1. Content Security Policy: Die Einstellungen der Seite haben das Laden einer Ressource auf self blockiert ("script-src http://localhost 'unsafe-inline'").
    • call to eval() or related function blocked by CSP: autocomplete.js (Line 253)
  2. #1139 – Got error 'this version of PCRE is compiled without UTF support at offset 0' from regexp
    • Error
      Static analysis:
      8 errors were found during analysis.
          Unrecognized keyword. (near "REGEXP" at position 209)
          Unexpected token. (near "'^/Blog/.+/.+/.+$'" at position 216)
          Unrecognized keyword. (near "AND" at position 235)
          Unexpected token. (near "p" at position 239)
          Unexpected token. (near "." at position 240)
          Unexpected token. (near "deleted" at position 241)
          Unexpected token. (near "<>" at position 249)
          Unexpected token. (near "'1'" at position 252)
      SQL query: Documentation
      SELECT p.page_id, p.owner_id, p.user_id, p.tag, p.title, p.created, p.comments, u.user_name AS owner FROM wacko_page p INNER JOIN wacko_user u ON (p.owner_id = u.user_id) WHERE p.comment_on_id = '0' AND p.tag REGEXP '^/Blog/.+/.+/.+$' AND p.deleted <> '1' ORDER BY p.created DESC LIMIT 0, 10
      MySQL said: Documentation
      #1139 - Got error 'this version of PCRE is compiled without UTF support at offset 0' from regexp
    • https://stackoverflow.com/ques[..]sing-regexp-in-mysql[link62]
    • <?php
      if ( ! extension_loaded('mbstring'))
        die('mb functions not loaded');
      if (1 != preg_match('/^.{1}$/u', "ñ", $UTF8_ar))
        die('PCRE is not compiled with UTF-8 support');

5.5.0 – distilled from error.log (PHP 7.0)

Undefined index: deleted in /class/wacko.php on line 1495
Undefined index: tag in /class/wacko.php on line 1507
Undefined index: page_lang in /class/wacko.php on line 1512

htmlspecialchars() expects parameter 1 to be string, array given in /class/wacko.php on line 3290

Undefined index: page_id in /class/wacko.php on line 1386

Undefined index: comment_on_id in /handler/page/show.php on line 12
Undefined index: deleted in /handler/page/show.php on line 43
Undefined index: latest in /handler/page/show.php on line 66
Undefined index: modified in /handler/page/show.php on line 71
Undefined index: user_name in /handler/page/show.php on line 72
Undefined index: page_lang in /class/wacko.php on line 4023
Undefined index: page_id in /handler/page/show.php on line 114
Undefined index: body_r in /handler/page/show.php on line 133
Undefined index: latest in /handler/page/show.php on line 137
Undefined index: body in /handler/page/show.php on line 138
Undefined index: page_id in /handler/page/show.php on line 138
Undefined index: latest in /handler/page/show.php on line 199
Undefined index: latest in /theme/_common/_header.php on line 19
Undefined index: description in /class/wacko.php on line 1032
Undefined index: page_id in /theme/default/appearance/header.php on line 83

Undefined index: page_id in /theme/default/appearance/header.php on line 166
Undefined index: modified in /theme/default/appearance/footer.php on line 20
Undefined index: comment_on_id in /theme/default/appearance/footer.php on line 46
Undefined index: page_id in /action/hashid.php on line 21

Undefined index: page_id in /action/hashid.php on line 27
Undefined index: handler in /class/wacko.php on line 4626

Undefined index: footer_comments in /class/wacko.php on line 6441
Undefined index: footer_files in /class/wacko.php on line 6441
Undefined index: footer_rating in /class/wacko.php on line 6441
Undefined index: hide_toc in /class/wacko.php on line 6441
Undefined index: hide_index in /class/wacko.php on line 6441
Undefined index: tree_level in /class/wacko.php on line 6441
Undefined index: allow_rawhtml in /class/wacko.php on line 6441
Undefined index: disable_safehtml in /class/wacko.php on line 6441
Undefined index: theme in /class/wacko.php on line 6441

Undefined index: page_id in /class/wacko.php on line 6451

Undefined index: modified in /class/wacko.php on line 6461

Undefined index: comment_on_id in /class/wacko.php on line 6476

Uninitialized string offset: 0 in /formatter/class/wackoformatter.php on line 330
Uninitialized string offset: 0 in /formatter/class/wackoformatter.php on line 440
Undefined offset: 3 in /formatter/class/wackoformatter.php on line 874

Invalid argument supplied for foreach() in /lib/Text_Highlighter/Highlighter/Renderer/Html.php on line 310

2. Unscheduled

2.1. Most Annoying Bugs

2.2. Core

  1. Extended Acls[link63]
  2. WackoFormatter[link64]: conversion from & to &
    1. You used an unescaped ampersand "&": this may be valid in some contexts, but it is recommended to use "&", which is always safe.
  3. place help text beside the acl settings and Registration (WikiName) for instance
  4. if ($method && $method != "show") unset($wacko->config["youarehere_text"]);
  5. /Users/DidierSpaier/ProposedSpecificationsForLanguagesHolding[link65]
  6. validate_reserved_words
  7. inherit theme from parent page
  8. config['hide_comments'] == true surpresses also recentycommented action what is not intended if you only want hide the comment panel
    • config['footer_comments'] -> only perpage
    • config['enable_comments'] -> global (incomplete implementation) -> see function user_allowed_comments()
  9. add license option (global / per page) to label pages / cluster and set them as meta tag and in footer
    1. footer: <a href="http://creativecommons.org/licenses/by/3.0/">CC-BY 3.0</a>
    2. meta tag: <link rel="license" href="http://creativecommons.org/licenses/by-sa/3.0/" />
  10. add namespaces for 
    1. category
    2. account
    3. ...
  11. https://developer.mozilla.org/[..]ccess_control#Origin[link66] (CSRF protection)
  12. rewrite search action

2.3. Cache

2.4. Themes

  1. <meta name='robots' content='index,follow,noarchive,noodp' />
  2. add compatible WackoWiki version to themes and check against current version
3. missing language in header / meta if !$this->page

2.5. Actions

  1. add more checks to registration
    1. email restrictions like domain etc.
  2. https://wackowiki.org/doc/?goback=Download – broken redirect after auto logout
  3. add filter [lang|category|etc] in pageindex, search, changes, ...

2.6. Handlers

  1. category: indicate the language of the shown categories
  2. Report this page
  3. show: it should also be possible to get an page via the 'page_id' (as permanent reference, eg. for external applications)
    1. redirect to tag to avoid double content
  4. upload: add option to 'Overwrite existing attachment of same name'
    • if same owner / admin
  5. page creation: check if new tag is too long and give a warnig -> VARCHAR(255), this cas is rather probably but possible
  6. Warn users when they try to move their user page that their account will not be renamed
  7. permissions: changing page owner also changes owner of the attached comments for the user doing the transition
    AND owner_id='".quote($this->dblink, $this->get_user_id())."'
    • adding option for comments (default off)

2.7. Formatters

  1. cleanwacko-> strip also file: links and formatter options (hl php ...)

2.8. Installer

  1. autodetect the language on the first page
  2. create a robot.txt with the installer
    • this makes only sense if the file is located behind the first slash / in the url else it will be ignored
  3. add better help box:
    ===Getting Help===
    To get help with WackoWiki, visit the Documentation - the wiki and forums are excellent resources.

2.8.1. Upgrade

  1. for Upgrade insert other aliases also in groups table
    • $config["aliases"] = array("Admins" => $config["admin_name"]);
  2. the installer asks for the Wiki admin password but ignores it later, so tho old password will be used

2.9. Database

2.10. Admin Panel

  1. protect Admins group and Admin user
  2. allow multiple admins login with personal credentials in addition to recovery password login (in case of db corruption)
  3. translate message sets in proper English
  4. Localize Admin panel -> admin/lang/xy.php
  5. refactor sections

2.11. Privacy Policy

2.12. Testing

2.13. Debugging

2.14. PHP Notices and Warnings

bugs:237[link69] -> set in config/constants.php

define('PHP_ERROR_REPORTING',		5); // PHP error reporting: 0 - off, 5 - all

and / or check \apache\logs\error.log

2.15. Translation

  1. Translate English placeholders

3. Documentation

  1. update documentation
    1. config
    2. actions
    3. syntax
  2. SQL cache -> info config / howto
  3. robots.txt
    1. useragents disabled by default
    2. location of robots.txt

4. Requests

  1. add function InviteGroup (allow/deny add/remove)
  2. Admin can upload unlimited
  3. Mediawiki and other wiki converter
    1. Mediawiki supports wackowiki but wackowiki cant import mediawiki!!!. Some media wiki themes recommended.
    2. Support for mediawiki.
  4. [formatting="default|wacko|html|simplebr"]
  5. make GUI elements optional via the user settings [GUI] [] bookmarks [] breadcrumbs [] etc.
  6. add new db field 'menu_tag' and 'sef_tag' for each page
  7. add options to turn off features like categories, referrers, ...
  8. receive all messages combined in one digest
    1. daily at 
    2. once per week on 
    3. once per month, on the day number
  9. option for allowed actions in comments
  10. move antispam.conf as badword to config
  11. SHA digest of page content (body)