WordPress 3.0 available
wordpress.org
wordpress.org
I've found this: http://blog.mixu.net/2010/05/17/setting-up-multisite-wordpre...
Which references this: http://www.interconnectit.com/840/wordpress-3-0-multisite-wi...
These assume you can edit your Apache conf, and many cloud hosts don't support that.
Then read this: http://ottopress.com/2010/wordpress-3-0-multisite-domain-map...
I use this exact method (and a subdirectory, not a subdomain install) to run multiple domains off on a WP 3.0 installation on cheap, shared, GoDaddy hosting. No apache config editing whatsoever.
Also appreciate the article references workarounds (eg., use trunk version of plugin). I'm suspicious of articles suggesting everything "just works".
Thank you, Otto.
- One DB server - The application server (wordpress install) - Cloudfiles with CDN enabled for speed.
Adding in multiple domains isn't hard either. Email me if you need help: j@jasonlbaptiste.com
It's possible to run WP in a secure manner. Just because some people don't doesn't mean you can't. It doesn't require crazy wget hacks, just updating. You can even automate it with SVN.
If anyone has questions or would like best practices for running WP in a secure manner, I'd be happy to answer them, here or over email -- m@mullenweg.com.
To this end we work with numerous third-party hosts to help them update their customers, and have invested significantly in a notification and upgrade system for 10k+ plugins, 1k+ themes, and of course the core software. This was a particular PITA because runs on so many platforms with wildly different constraints and configurations. We blog, tweet, and email 200k people whenever there's a new release and offer free help on our forums to anyone who is stuck. Someday we might even offer auto-update in core just like many hosts already do.
My comment was more aimed at the HN audience which might want pro tips for staying updated or more defense in depth. For example I have a cron job run `svn up` on my site every morning which keeps it up to date whether I'm in front of my computer or on a beach sipping mai tais.
Can you really trust that not to randomly break your site? Surely you'll run into regressions or backwards-incompatibilities at some point?
Many folks in the WP community, including myself, svn up to trunk. I wouldn't recommend that for the general public, but I think it's only broken my site once in the past year and I fixed it by running svn up again. If I was smarter I would script it to svn up, check the site, revert if it was blank. WP.com syncs to WordPress trunk pretty regularly, as well, sometimes daily depending on where WP is in its release cycle or if we have to do any database migrations.
WordPress has secure defaults and the codex does a good job of providing instructions if you really want to go modifying the default.
There will always be tutorials out there saying
chmod 777 *
Rookie users will follow these tutorials and then blame WP because they find a whole bunch of malicious scripts show up in their wordpress directory.EDIT: formatting
http://codex.wordpress.org/Hardening_WordPress
(And much is applicable to many web apps besides WordPress.)
One thing I don't understand, is why I can't access the admin over SSL if the Wordpress domain isn't the Apache SSL domain? For example, I can't go to https://example.com/domains/mydomain.com/wp-admin/ without getting a failed redirect. This is a major annoyance, as I can't set up another SSL site on the server without leasing another IP.
Renaming wp-admin is not currently possible. This is slated for future versions though.
And the reason WordPress doesn't use relative URLs is because it uses a rewrite system for most of the site. With the permalink system, most of the URLs don't actually exist as real directories, but are simply indicators to tell WordPress what sort of things you're looking for. Now, I grant you that this is not the case for the admin side of things, which uses direct links to files and the like. Those links there, however, are relative.
However, the reason the admin redirects to the right URL is because of the secure cookie handling. Cookies in WordPress are carefully controlled as to which URLs they are sent to, they're not just indiscriminately sent to the whole site. If you're using SSL Login and Admin, then the login cookies are only sent to the SSL side of things, and only to requests in the admin directories, etc. Other cookies are sent to the normal non-SSL side, which will identify you for login purposes, but not allow you administrative access. All this careful cookie handling means that the correct domain must be present for everything to work. It can't work through some other domain that it doesn't know about.
Not sure on the second question.
Headed to Refresh Pittsburgh tonight? There's a presentation about WP3.
I didn't know it was happening tonight. Maybe. We'll see. I've been on a roll with Hackety Hack lately, and I want to make sure I have a few hours to put in.
There are events pretty much every month, but I haven't made any in a while this will be my first Refresh Pittsburgh all year. Make sure ya say hello to this guy: http://bit.ly/9jELdY (me)
Might want to add RefreshPittsburgh, Devhouse Pittsburgh and Dorkbot Pittsburgh to the events calendar, too.
Security aside, MT has lots of issues -- performance (or lack thereof) being one of them and bad upgrades being another. After the third time an upgrade broke some sites I manage, I gave up and migrated some sites to WordPress and some to Drupal. Have yet to come across the same issue.
I'm not being funny, it happens with nearly every WP release because they do everything last minute.
If I win, you have to drop everything and fix the backtick code bug on bbpress.org
ps. I also consider the bet won if there is a major issue posted on TRAC within a week, even if you delay a bugfix release.
Can you email me details of the backtick bug?
Now if I could just figure out how to get the darn thing to work properly.
A good article on custom post types: http://kovshenin.com/archives/custom-post-types-in-wordpress...