4 3.5.0.0 (not yet released)
5 + rfe #2021981 [interface] Add support for mass prefix change.
6 + "up to date" message on main page when current version is up to date
7 + Update to jQuery 1.6.2
8 + Patch #3256122 [search] Show/hide db search results
9 + Patch #3302354 Add gettext wrappers around a message
10 + Remove deprecated function PMA_DBI_get_fields
11 + rfe #2098927 Remember recent tables
12 + rfe #3078542 Remember the last sort order for each table
13 + AJAX for Create table in navigation panel
14 + rfe #3310562 Wording about Column
15 + AJAX for Add a user in Database privileges
16 + Patch #3271804 for rfe #3177495, new DisableMultiTableMaintenance directive
17 + [interface] Reorganised server status page.
18 + [interface] Changed way of generating charts.
19 + rfe #939233 [interface] Flexible column width
20 + [interface] Mouse-based column reordering in query results
21 + AJAX for Insert to a table from database Structure page
22 - Patch #3316969 PMA_ajaxShowMessage() does not respect timeout
23 + AJAX for Change on multiple rows in table Browse
24 + [interface] Improved support for stored routines
25 + [display] More options for browsing GIS data
26 + [interface] Support for spatial indexes
27 + [display] GIS data visualization
28 + AJAX for table structure multiple-column change
29 + AJAX for table structure index edit
30 + Show/hide indexes in table Structure
31 + More compact navigation bar
32 + Display direction (horizontal/vertical) no longer displayed by default
33 + Shift/click support in database Structure
34 + Show/hide column in table Browse
35 - bug #3353856 [AJAX] AJAX dialogs use wrong font-size
36 - bug #3354356 [interface] Timepicker does not work in AJAX dialogs
37 + AJAX for table Structure Indexes Edit
38 + AJAX for table Structure column Change
39 + [interface] Improved support for events
40 + [interface] Improved support for triggers
41 + [interface] Improved server monitoring
42 + AJAX for table Structure column Add
43 + AJAX for table Operations copy table
44 - bug #3380946 [export] no uid Query result export (Suhosin limit)
45 + Grid editing in browse mode (replaces row inline edit)
46 + Zoom-search in table Search
47 + [interface] Editor for GIS data
48 + [import] Import GIS data from ESRI Shapefiles
49 + [interface] 'Function based search' for GIS data
50 + Support Drizzle database
51 - bug #3356456 [interface] Interface problems for queries having LIMIT clauses
52 + [interface] Remove DefaultPropDisplay feature
53 - bug #3299486 [prettyprint] Order By in a query containing comment character
54 + [interface] Improved ENUM/SET editor
55 + patch #3428376 [pmadb] pmadb on a different MySQL server
56 + patch #3410688 [interface] Improving field size for character columns
57 - [usability] Removed an unnecessary AJAX request from database search
58 - bug #3302419 [navi] Tabs break when squeezing page
59 + rfe #3406797 [navi] Stick table tools to top of page on scroll
60 + rfe #1632106 [interface] Improved error handling
61 + patch #3432835 [interface] Add useful intermediate pages to pageselector
62 + [interface] Improved index editor
64 3.4.9.0 (not yet released)
65 - bug #3442028 [edit] Inline editing enum fields with null shows no dropdown
67 3.4.8.0 (not yet released)
68 - bug #3425230 [interface] enum data split at space char (more space to edit)
69 - bug #3426840 [interface] ENUM/SET editor can't handle commas in values
70 - bug #3427256 [interface] no links to browse/empty views and tables
71 - bug #3430377 [interface] Deleted search results remain visible
72 - bug #3428627 [import] ODS import ignores memory limits
73 - bug #3426836 [interface] Visual column separation
74 - bug #3428065 [parser] TRUE not recognized by parser
75 + patch #3433770 [config] Make location of php-gettext configurable
76 - patch #3430291 [import] Handle conflicts in some open_basedir situations
77 - bug #3431427 [display] Dropdown results - setting NULL does not work
78 - patch #3428764 [edit] Inline edit on multi-server configuration
79 - patch #3437354 [core] Notice: Array to string conversion in PHP 5.4
80 - [interface] When ShowTooltipAliasTB is true, VIEW is wrongly shown as the
81 view name in main panel db Structure page
82 - bug #3439292 [core] Fail to synchronize column with name of keyword
83 - bug #3425156 [interface] Add column after drop
84 - [interface] Avoid showing the password in phpinfo()'s output
85 - bug #3441572 [GUI] 'newer version of phpMyAdmin' message not shown in IE8
86 - bug #3407235 [interface] Entering the key through a lookup window does not reset NULL
87 - [security] Self-XSS on database names (Synchronize), see PMASA-2011-18
88 - [security] Self-XSS on database names (Operations/rename), see PMASA-2011-18
89 - [security] Self-XSS on column type (Create index), see PMASA-2011-18
90 - [security] Self-XSS on column type (table Search), see PMASA-2011-18
91 - [security] Self-XSS on invalid query (table overview), see PMASA-2011-18
94 - [security] Fixed possible local file inclusion in XML import
98 - bug #3418610 [interface] Links in navigation when $cfg['MainPageIconic'] = false
99 - bug #3418849 [interface] Inline edit shows dropdowns even after closing
100 - bug [view] View renaming did not work
101 - bug [navi] Wrong icon for view (MySQL 5.5)
102 - bug #3420229 [doc] Missing documentation section
103 - bug #3423725 [pdf] Broken PDF file when exporting database to PDF
104 - [core] Allow to set language in URL
105 - bug #3425184 [doc] Fix links to PHP documentation
106 - bug #3426031 [export] Export to bzip2 is not working
109 - patch #3404173 InnoDB comment display with tooltips/aliases
110 - bug #3404886 [navi] Edit SQL statement after error
111 - bug #3403165 [interface] Collation not displayed for long enum fields
112 - bug #3399951 [export] Config for export compression not used
113 - bug #3400690 [privileges] DB-specific privileges won't submit
114 - bug #3410604 [config] Configuration storage incorrect suggested table name
115 - bug #3383572 [interface] Cannot execute saved query
116 - bug #3411535 [display] Full text button unchecks results display options
117 - bug #3411224 [display] Broken binary column when 'Show binary contents' is not set
118 - bug #3411633 [core] Call to undefined function PMA_isSuperuser()
119 - bug #3413743 [interface] Display options link missing after search
120 - bug #3324161 [core] CSP policy causing designer JS buttons to fail
121 - bug #3412862 [relation] Relations/constraints are dropped/created on every change
122 - bug #3390832 [display] Delete records from last page breaks search
123 - bug #3392150 [schema] PMA_User_Schema::processUserChoice() is broken
124 - bug #3414744 [core] External link fails in 3.4.5
125 - patch #3314626 [display] CharTextareaRows is not respected
126 - bug #3417089 [synchronize] Extraneous db choices
127 - [security] Fixed local path disclosure vulnerability, see PMASA-2011-15
128 - [security] Fixed XSS in setup (host/verbose parameter), see PMASA-2011-16
131 - bug #3375325 [interface] Page list in navigation frame looks odd
132 - bug #3313235 [interface] Error div misplaced
133 - bug #3374802 [interface] Comment on a column breaks inline editing
134 - patch #3383711 [display] Order by a column in a view doesn't work in some cases
135 - bug #3386434 [interface] Add missing space to server status
136 - [core] Remove library PHPExcel, due to license issues
137 - [export] Remove native Excel export modules (xls and xlsx formats)
138 - [import] Remove native Excel import modules (xls and xlsx formats)
139 - bug #3392920 [edit] BLOB emptied after editing another column
140 - [security] Fixed XSS in Inline Edit on save action, see PMASA-2011-14
141 - [security] Fixed XSS with db/table/column names, see PMASA-2011-14
144 - bug #3323060 [parser] SQL parser breaks AJAX requests if query has unclosed quotes
145 - bug #3323101 [parser] Invalid escape sequence in SQL parser
146 - bug #3348995 [config] $cfg['Export']['asfile'] set to false does not select asText option
147 - bug #3340151 [export] Working SQL query exports error page
148 - bug #3353649 [interface] "Create an index on X columns" form not validated
149 - bug #3350790 [interface] JS error in Table->Structure->Index->Edit
150 - bug #3353811 [interface] Info message has "error" class
151 - bug #3357837 [interface] TABbing through a NULL field in the inline mode resets NULL
152 - remove version number in /setup
153 - bug #3367993 [usability] Missing "Generate Password" button
154 - bug #3363221 [display] Missing Server Parameter on inline sql query
155 - bug #3367986 [navi] Drop field -> lost active table
156 - remove misleading comment on the "Rename database" interface
157 - bug #3374374 [interface] Fix footnote for inexact count while browsing
158 - bug #3372807 [interface] Fix security warning link in setup
159 - bug #3374347 [display] Backquotes in normal text on import page
160 - bug #3358750 [core] With Suhosin, urls are too long in edit links
161 - [security] Missing sanitization on the table, column and index names leads to XSS vulnerabilities, see PMASA-2011-13
164 - [security] Fixed XSS vulnerability, see PMASA-2011-9
165 - [security] Fixed local file inclusion vulnerability, see PMASA-2011-10
166 - [security] Fixed local file inclusion vulnerability and code execution, see PMASA-2011-11
167 - [security] Fixed possible session manipulation in swekey authentication, see PMASA-2011-12
170 - [security] Fixed possible session manipulation in swekey authentication, see PMASA-2011-5
171 - [security] Fixed possible code injection incase session variables are compromised, see PMASA-2011-6
172 - [security] Fixed regexp quoting issue in Synchronize code, see PMASA-2011-7
173 - [security] Fixed filtering of a file path, which allowed for directory traversal, see PMASA-2011-8
176 - bug #3311170 [sync] Missing helper icons in Synchronize
177 - patch #3304473 [setup] Redefine a lable that was wrong
178 - bug #3304544 [parser] master is not a reserved word
179 - bug #3307616 [edit] Inline edit updates multiple duplicate rows
180 - patch #3311539 [edit] Inline edit does not escape backslashes
181 - bug #3313210 [interface] Columns class sometimes changed for nothing
182 - patch #3313326 [interface] Some tooltips do not disappear
183 - bug #3315720 [search] Fix search in non unicode tables
184 - bug #3315741 [display] Inline query edit broken
185 - patch #3317206 [privileges] Generate password option missing on new accounts
186 - bug #3317293 [edit] Inline edit places HTML line breaks in edit area
187 - bug #3319466 [interface] Inline query edit does not escape special characters
188 - minor XSS (require a valid token)
191 - bug #3301249 [interface] Iconic table operations does not remove inline edit label
192 - bug #3303869 [interface] Unnecessary scrolling on Databases page
193 - patch #3303813 [setup] Define a label that was missing
194 - bug #3305606 [interface] Show all button wraps on privileges page
195 - bug #3305517 [config] Config for export compression not used
196 - bug #3305883 [interface] Table is dropped regardless of confirmation
197 - [auth] Fixed error handling for signon auth method.
198 - bug #3276001 [core] Avoid caching of index.php.
199 - bug #3306958 [interface] Unnecessary Details slider
200 - bug #3308476 [interface] "Show all" not persistent after a sort
201 - bug #3308072 [auth] Version disclosure to anonymous visitors
202 - bug #3306981 [interface] pmahomme and table statistics
205 - bug #3301108 [interface] Synchronize and already configured host
206 - bug #3302457 Inline edit and $cfg['PropertiesIconic']
207 - Patch #3302313 Show a translated label
208 - bug #3300981 [navi] Table filter is case sensitive
209 - bug #3285929 [privileges] Revert temporary fix
210 - bug #3302872 [synchronize] Synchronize and user name
211 - bug #3302733 [core] Some browsers report an insecure https connection
212 - [security] Make redirector require valid token
215 + rfe #2890226 [view] Enable VIEW rename
216 + rfe #838637 [privileges] Export a user's privileges
217 - [core] Updated mootools to fix some glitches with Safari.
218 + rfe #2816943 [interface] Add REGEXP ^...$ to select dialog.
219 + rfe #2924956 [interface] Add insert ignore option to editing row.
220 + rfe #2838080 [interface] Show warning when javascript is disabled.
221 + rfe #2823707 [edit] Call UUID function separately to show it in insert.
222 + rfe #2420684 [export] Allow export of timestamps in UTC.
223 + [core] Remove config data from session as it brings chicken-egg problem.
224 + [core] Cookie path now honors PmaAbsoluteUri.
225 + rfe #2393597 [core] phpMyAdmin honors https in PmaAbsoluteUri.
226 + rfe #1778337 [core] Try moving tables by RENAME and fail to CREATE/INSERT if that fails.
227 + rfe #1721189 [core] Force reload js on code change.
228 + rfe #1954161 [interface] Do not display long numbers in server status.
229 + rfe #2033616 [edit] Add option to just display insert query.
230 + rfe #1435032 [interface] Move SSL status to the end, it is usually empty.
231 + rfe #1340812 [interface] Show numbers of columns in table structure.
232 + rfe #1186511 [inrerface] Add link to reload navigation frame.
233 + rfe #2936156 [auth] Signon authentication forwards error message through session data.
234 + rfe #2835109 [interface] Move ^1 to the end of message.
235 + rfe #854911 [interface] Grey out non applicable actions in structure
236 + [interface] Allow to create new table from navigation frame (in light mode).
237 + rfe #1025696 [browse] Add direct download of binary fields.
238 - [browse] Properly display NULL value for BLOB.
239 - rfe #1516803 [edit] Allow to set BLOB to/from NULL with ProtectBinary.
240 - [edit] Do not default to UNHEX when using file upload.
241 - rfe #1379201 [core] Add option to configure session_save_path.
242 + [interface] Provide links to documentation in highlighted SQL.
243 + [interface] It is now possible to bookmark most pages in JS capable browser.
244 - bug #2936482 [core] Fix SSL detection.
245 + rfe #2937850 [doc] Add some hints to chk_rel.php for quick setup.
246 + rfe #2938579 [interface] Add class to some elements for easier theming.
247 + rfe #2937840 [doc] Add some interesting configs to config.sample.inc.php.
248 + rfe #2792992 [doc] Added advice to re-login after changing pmadb settings
249 + patch #2952353 [interface] Prefill "Copy table to" in tbl_operations.php, thanks to iinl
250 + [lang] Add English (United Kingdom) translation, thanks to Robert Readman.
251 + patch #2948421 [auth] HTTP Basic auth realm name,
252 thanks to Harald Jenny - haraldj
253 - bug #2954916 [interface] Do not insert doc links to not formatted SQL.
254 + [lang] Chinese Simplified update, thanks to Shanyan Baishui - rimyxp
255 + [lang] Turkish update, thanks to Burak Yavuz
256 + rfe #2963310 [interface] Focus TEXTAREA "sql_query" on click on "SQL" link
257 + [lang] Uzbek update, thanks to Orzu Samarqandiy
258 + rfe #2958013 [import] After import, also list uploaded filename, thanks
259 to Pavel Konnikov and Herman van Rink
260 + patch #2974341 [structure] Clicking on table name in db Structure should
261 Browse the table if possible, thanks to bhdouglass - dougboybhd
262 + patch #2975533 [search] New search operators, thanks to
264 + patch #2967320 [designer] Colored relations based on the primary key,
265 thanks to GreenRover - greenrover
266 - [core] Provide way for vendors to easily change paths to config files.
267 + patch #2979922, rfe #2804874 [interface] Add inline query editing, thanks to Muhammd Adnan.
268 - bug #2966752 [setup] Allow to configure changes tracking in setup script.
269 + patch #2981165 [edit] Optionally disable the Type column,
270 thanks to Brian Douglass - bhdouglass
271 + patch #2984058 [edit] Buttons for quicky creating common SQL queries, thanks
273 + patch #2984337 [interface] Convert loading of export/import to jQuery ready
274 event, thanks to sutharshan.
275 - [edit] CURRENT_TIMESTAMP is also valid for datetime fields.
276 - patch #2985068 [engines] Fix parsing of PBXT status, thanks to Madhura Jayaratne.
277 - patch #2986073 [interface] Convert upload progress bar to jQuery, thanks to
279 - patch #2983960 [interface] Add javascript validation of datetime input,
280 thanks to Sutharshan Balachandren.
281 - rfe #2981999 [interface] Default sort order is now SMART.
282 - rfe #2972969 [interface] Fix flipping of headers in non-IE browsers.
283 + rfe #2964518 [interface] Allow to choose servers from configuration for
285 + rfe #2988633 [relation] Improve ON DELETE/ON UPDATE drop-downs
286 + rfe #2988629 [relation] Improve labels in relation view
287 + rfe #2983207, patch #2988715 [interface] Use jQuery calendar dialog, thanks
289 + [doc] Incorporate synchronisation docs into main document.
290 + [core] Include Content Security Policy HTTP headers.
291 - bug #3004216 [CSS] Field attributes use inline CSS
292 - patch #2999595, rfe #2998130 [interface] Cleanup navigation frame.
293 - patch #3025161 [core] Prevent sending of unnecessary cookies,
294 thanks to Piotr Przybylski - crackpl
295 - bug [password] Generate password only available if JS is enabled
296 (fixed for Privileges and Change password)
297 - [core] RecodingEngine now accepts none as valid option.
298 + [core] Dropped AllowAnywhereRecoding configuration variable.
299 - rfe #3016457 [interface] Define tab order in SQL form to allow easier tab
301 + [core] Centralized format string expansion, @VARIABLES@ are recommended way
302 now, used by file name templates, default queries, export and title
304 + [validator] SQL validator works also with SOAP PHP extension.
305 - [interface] Better formatting for SQL validator results.
306 - [doc] The linked-tables infrastructure is now called phpMyAdmin
307 configuration storage.
308 - [interface] Move drop/empty links from being tabs to Operations tab.
309 - [interface] Fixed rendering of error/notice/info titles background.
310 - patch #3038293 [doc] Language and grammar fixes,
311 thanks to Isaac Bennetch - ibennetch
312 - patch #3038312 [export] JSON export,
313 thanks to Hauke Henningsen - blubberkeks152
314 - rfe #1494550 [interface] Editor for SET/ENUM fields.
315 - rfe #2649375 [interface] Simplified interface to backup/restore.
316 - rfe #2973909 Users preferences
317 - [relations] Dropped WYSIWYG-PDF configuration variable.
318 - rfe #806035, #686260 [relations] Export relations to Dia, SVG and others
319 + [interface] Added charts to status tab, profiling page and query results
320 + [interface] AJAXification on various pages
321 - [core] Remove last remaining parts of profiling code which was removed in 2006.
322 - bug #3042665 [parser] Add workaround for MySQL way of handling backtick.
323 - bug #3056610 [interface] Removed modification options for information_schema
324 + patch #3055886 [config] Add Left frame table filter visibility config option, thanks to eesau
325 - [core] Force generating of new session on login
326 + rfe #1105678 [interface] Drop page-break-before as it is useless for smaller
328 + rfe #2956556 [interface] Allow to wrap enum values.
329 - bug #1669459 [interface] Do not automatically mark PDF schema rows to delete
330 - bug #3087682 [interface] Do not apply LeftFrameDBSeparator on first character.
331 + rfe #3111455 [interface] Column highlighting and marking in table view
332 + Visual query builder
333 - bug #3115519 [interface] Prevent long queries from being shown in confirmation popup
334 - patch #3112792 [navi] Left panel table grouping incorrect,
335 thanks to garas - garas
336 - bug #3123433 [interface] Avoid double escaping of MySQL errors.
337 - [interface] Use less noisy message and remove disable link on server charts and database statistics.
338 + rfe #3141330 [relation] When displaying results, show a link to the foreign
339 table even when phpMyAdmin configuration storage is not active
340 - bug #3141327 [relation] Foreign key input options
341 - [export] Better handling of export to PHP array.
342 - rfe #3158867 [privileges] No DROP DATABASE warning if you delete a user
343 - [interface] Add link to documentation for status variables.
344 - [security] Redirect external links to avoid Referer leakage.
345 - [interface] Default to not count tables in database.
346 - patch #3172172 [interface] Shortcut for copying table row.
347 - bug #3175227 [auth] Reset user cache on login.
348 - rfe #3148361 [interface] Replace hard coded limit with $cfg['LimitChars'].
349 - bug #3177136 [interface] Indicate that bookmark is being used on browse.
350 - [interface] Indicate shared bookmarks in interface.
351 - patch #3176420 [Search] Ajaxify browse and delete criteria in DB Search,
352 thanks to Thilanka Kaushalya
353 - [interface] New default theme pmahomme, dropped darkblue_orange theme.
354 - rfe #2936155 [auth] Allow to pass additional parameters using signon method.
355 - rfe #1640812 [auth] Add example for OpenID authentication using signon method.
356 - rfe #1312657 [dbi] Default to mysqli extension.
357 - rfe #1168350 [interface] Add clear button to SQL edit box.
358 - [core] Update library PHPExcel to version 1.7.6
359 - bug #3206876 [core] Work without mbstring installed.
360 - rfe #3196075, patch #3212068 [interface] Add links to variables documentation.
361 - bug #3208723 [import] Fix import of utf-8 XML files.
362 - bug #3039384 [auth] Force signon auth on signon URL change.
363 - bug #3168733 [core] Synchronization does not honor AllowArbitraryServer
364 - bug #3134495 [synchronization] Data containing single quotes prevents sync,
366 - Remove the custom color picker feature
367 - bug #3285929 [privileges] Don't fail silently on missing priviledge to execute REVOKE ALL PRIVILEGES
369 3.3.11.0 (not yet released)
371 3.3.10.1 (2011-05-20)
372 - [security] XSS on Tracking page
374 3.3.10.0 (2011-03-19)
375 - patch #3147400 [structure] Aria table size printed as unknown,
376 thanks to erickoh75 - erickoh75
377 - patch #3150164 [structure] Ordering by size gives incorrect results,
378 thanks to Madhura Jayaratne - madhuracj
379 - bug #3153409 [core] 0 row(s) affected
380 - bug #3155842 [core] Edit relational page and page number
381 - [security] Minor security fixes, see PMASA-2010-9 and PMASA-2010-10
382 - [lang] German update, thanks to to jannicars@users.sourceforge.net.
385 - [security] SQL injection, see PMASA-2011-2
388 - [security] Path disclosure, see PMASA-2011-1
391 - bug [doc] Fix references to MySQL doc
392 - patch #3101490 Default function for TIMESTAMP, thanks to jirand - jirand
393 - bug #3103853 [js] Double quotes were not escaped in generated js
394 - bug #3077463 [core] Events were not copied when copying/renaming database
395 - bug #1762306 [core] Copy database with view of a view
396 - patch #3117535 [replication] Add quotes to database in initial statement,
397 thanks to Craig Duncan - duncan3dc
398 - bug #3112614 [pdf schema] Scratchboard for PDF pages not working
399 - bug #3125606 [parser] Query for table "level" causes strange display
400 - bug #3127904 [parser] Close all opened round brackets indents
402 --- Older ChangeLogs can be found on our project website ---
403 http://www.phpmyadmin.net/old-stuff/ChangeLogs/
405 # vim: et ts=4 sw=4 sts=4
406 # vim: ft=changelog fenc=utf-8
407 # vim: fde=getline(v\:lnum-1)=~'^\\s*$'&&getline(v\:lnum)=~'\\S'?'>1'\:1&&v\:lnum>4&&getline(v\:lnum)!~'^#'
408 # vim: fdn=1 fdm=expr