RobS wrote:
Yeah, we probably should have sent an e-mail to more bridge developers or done something else to communicate the changes, we realize that now and you can consider it a lesson learned. We will try to do better next time.
Rob,
I highly appreciate your clarification and no need for further apologies imho.
The
try to do better remark is hopeful but not enough and allow me to explain why without personal- or offense at all... Trying to help as usual ;)
ProcessThe issue is that new release are done for instance to secure issues such as security, consistency, bug fixes etc. This is perfect and extremely important....end-users (and I am also an end-user) are mostly wildly enthusiastic at the moment something new of/from this fantastic product is released and want to play immediately with this new toy. The missing link here towards me as end-user is that I should have received a warning with the release that product X,Y,Z would be affected and that users had to wait till the X,Y,Z were updated. No offense but it was known that CB and VM were affected and it was very clear that Bridges and other stuff would be affected as well....(if login issues arise with CB and VM they will also arise on similar coded solutions) It was know upon release that CB and VM were not ready and THAT should have been communicated. I completely agree with the fact that "core" has patched the security holes as rapidly as possible and Beat was indeed the initiator for this and he was darn right...
I still agree that it should have been released asap it to secure the sites asap but the way how this is done now has caught the entire community by total surprise. Realize that we have the end-users (who spend just like you and me days and nights on discovering and building and spending tons of money of their savings on extensions or training or templates) who have contacted us (literally in tears) that everything they have done was (in their opinion) destroyed. So
trying to do it better is not enough! We
must do it better!
Process impiovementCore and Quality have enough methods to communicate with the entire development community. It is done for 1.5 so it could have been done with this release in advance as well. We have the best source available to make development announcements so developers could react in time and that is
http://dev.joomla.org/... So email is never the best method.....(spam is one of those reasons....) So any message/signal could have been send out to the development community also early July on the Development Site? (note: Than the responsibility would have been with 3rd parties......)
The announcement should never be done after the software iis published.... That is the biggest issue what is causing much pain and needless problems for the end-users
>> Appoint a focus-person for 3rd party communications and bridging internal issues responsible for these releases
TestingOne of the major issues seems to me related to being kicked out of admin backend. A Testing Team would have logged in in admin I assume and would have discovered this in advance? I know we have a testing team and they should also test 1.0.x versions (!) The person mentioned above could have an assuring task here?
Communication end-userAllow people who work on daily basis and who "talk" daily with the real end-users to support and facilitate "readable and understandable" end-user announcements before they are published. I am sure you will be able to find these kinds of persons on the forum

Example:
Quote:
Joomla! 1.0.13 [ Sunglow ] is now available for download.
Joomla! 1.0.13 features:
* Several low-risk security fixes
* Improved password storage system
* Easier control over Register Globals Emulation
* An Itemid backwards compatibility setting
* Improved administrative session security
* Improved HTTP/HTTPS switchover support
Before installing the release be informed about the following!
This release will break the compatibility in the next couple of weeks on certain extensions such as Community Builder, Virtuemart and many Bridges. Until you have seen a message on the extensions developer's website that it is safe to install the new version you should not install this upgrade otherwise your extensions do not work any longer. Please approach your extension developer for patches since they are aware that this security release is provided to the users.
We have carefully taken the issues as described in consideration but the fact that this release features several improvements to the password storage system designed to help protect the future security of your Joomla! powered website was for us of higher priority than waiting till 3rd parties had finished coding adaptations to the new storage mechanism.
I hope this is read as it should be ready namely not as critics but as positive contribution.............
Cheers and as always with respect for all efforts
Leo