<?xml version="1.0" encoding="utf-8"?>
<!--RSS generated by Flaimo.com RSS Builder [2026-08-25 18:50:55]-->
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"><channel><docs>https://bugs.xmbforum2.com/</docs><link>https://bugs.xmbforum2.com/</link><description><![CDATA[XMB Forum Bugs - Issues]]></description><title>XMB Forum Bugs - Issues</title><image><title>XMB Forum Bugs - Issues</title><url>https://bugs.xmbforum2.com/images/xmb-logo.gif</url><link>https://bugs.xmbforum2.com/</link><description><![CDATA[XMB Forum Bugs - Issues]]></description></image><language>en</language><category>All Projects</category><ttl>10</ttl><dc:language>en</dc:language><sy:updatePeriod>hourly</sy:updatePeriod><sy:updateFrequency>1</sy:updateFrequency><item><title>0000931: Implement TOTP for 2FA</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=931</link><description><![CDATA[The 2FA security standards are slowly gaining popularity.  Here are some ideas for XMB integration:&lt;br /&gt;
&lt;br /&gt;
- Allow each user to enable or disable 2FA for login.&lt;br /&gt;
- Require at least two enrolled devices or a backup code.&lt;br /&gt;
- Improve the user lockout experience by offering to unlock via 2FA.&lt;br /&gt;
- Give Super Admins the most strict lockout policy.&lt;br /&gt;
- Figure out how all of this will interface with existing features.]]></description><category>New Features</category><pubDate>Tue, 25 Aug 2026 18:42:37 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=931</guid><comments>https://bugs.xmbforum2.com/view.php?id=931#bugnotes</comments></item><item><title>0000930: Renaming a User Shouldn't Log Out the Admin</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=930</link><description><![CDATA[The Session API changed for user logout, and the new argument isn't supplied here:&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;https://github.com/miqrogroove/xmb/blob/b1898487318785d25e28264a9a258fab58d48ded/include/admin.inc.php#L90&quot; rel=&quot;noopener&quot;&gt;https://github.com/miqrogroove/xmb/blob/b1898487318785d25e28264a9a258fab58d48ded/include/admin.inc.php#L90&lt;/a&gt;]]></description><category>Bugs</category><pubDate>Fri, 21 Aug 2026 06:58:30 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=930</guid><comments>https://bugs.xmbforum2.com/view.php?id=930#bugnotes</comments></item><item><title>0000929: Admin Restrictions Manager has Hard-Coded Text</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=929</link><description><![CDATA[See the admin_restrictions_start.php and admin_restrictions_end.php templates for untranslated English text.]]></description><category>Translation Defects</category><pubDate>Thu, 20 Aug 2026 19:33:50 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=929</guid><comments>https://bugs.xmbforum2.com/view.php?id=929#bugnotes</comments></item><item><title>0000928: Implement the NoDiscard Attribute</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=928</link><description><![CDATA[PHP 8.5 introduced a &quot;NoDiscard&quot; attribute that can emit warnings if a function or method's return value is never used.  Some limited instances of this might be good in the long run.]]></description><category>New Features</category><pubDate>Thu, 20 Aug 2026 15:08:04 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=928</guid><comments>https://bugs.xmbforum2.com/view.php?id=928#bugnotes</comments></item><item><title>0000876: PHP 8.6 Compatibility</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=876</link><description><![CDATA[Items expected to affect XMB compatibility with PHP 8.6:&lt;br /&gt;
&lt;br /&gt;
Type casting a string that contains alphanumeric data will cause an error.  No more (int) '56 stuff' allowed.  (still under discussion)&lt;br /&gt;
&lt;br /&gt;
Function is_integer() will be deprecated (confirmed).]]></description><category>Research Tasks</category><pubDate>Thu, 20 Aug 2026 08:32:09 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=876</guid><comments>https://bugs.xmbforum2.com/view.php?id=876#bugnotes</comments></item><item><title>0000817: Site Health Panel</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=817</link><description><![CDATA[Would like ability to view phpinfo() output, as well as stats with feedback about overall operation.&lt;br /&gt;
&lt;br /&gt;
Desired features:&lt;br /&gt;
- Status of needed PHP extensions.&lt;br /&gt;
- Status of the opcache capacity.]]></description><category>New Features</category><pubDate>Mon, 17 Aug 2026 19:47:04 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=817</guid><comments>https://bugs.xmbforum2.com/view.php?id=817#bugnotes</comments></item><item><title>0000919: Translate Remaining Installer Text</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=919</link><description><![CDATA[The cinst.php file has several areas of untranslated English text that need to be migrated.]]></description><category>Translation Defects</category><pubDate>Mon, 17 Aug 2026 19:36:00 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=919</guid><comments>https://bugs.xmbforum2.com/view.php?id=919#bugnotes</comments></item><item><title>0000922: Translate the Template Output Comments</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=922</link><description><![CDATA[When tagging template boundaries in class Template, the comment text should be in the forum's default language rather than always English.]]></description><category>Translation Defects</category><pubDate>Mon, 17 Aug 2026 19:35:24 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=922</guid><comments>https://bugs.xmbforum2.com/view.php?id=922#bugnotes</comments></item><item><title>0000927: Posting Ban Option in Profile Editor</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=927</link><description><![CDATA[It doesn't make sense that the U2U/Posting ban option is only found in the Admin Member search page.  This needs to be easier to find in the profile editor.]]></description><category>New Features</category><pubDate>Mon, 17 Aug 2026 19:33:59 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=927</guid><comments>https://bugs.xmbforum2.com/view.php?id=927#bugnotes</comments></item><item><title>0000926: Incorrect Column Count for IP Banning Element</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=926</link><description><![CDATA[When the host name lookup was removed from IP Banning for v1.9.11, the corresponding column count wasn't adjusted.]]></description><category>Bugs</category><pubDate>Sun, 16 Aug 2026 05:30:55 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=926</guid><comments>https://bugs.xmbforum2.com/view.php?id=926#bugnotes</comments></item><item><title>0000925: Undefined variable $curgroup</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=925</link><description><![CDATA[The $curgroup variable is not correctly initialized in template admin_forums_list_grouped_subs.php.  Previous versions used a sloppy code path to create this variable, which was not considered when the template was migrated to the new processing system.]]></description><category>Bugs</category><pubDate>Sat, 15 Aug 2026 20:15:17 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=925</guid><comments>https://bugs.xmbforum2.com/view.php?id=925#bugnotes</comments></item><item><title>0000924: Make Names Read-Only in Admin Forum List</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=924</link><description><![CDATA[Switching the forum name textboxes to simple link text in the admin forum list solves three problems:&lt;br /&gt;
&lt;br /&gt;
1. We no longer need a separate &quot;More Options...&quot; link for every forum.&lt;br /&gt;
&lt;br /&gt;
2. The forum list is too busy and mass editing of names was never necessary.&lt;br /&gt;
&lt;br /&gt;
3. The forum list is too busy and the mass delete feature was never needed nor labeled anyway.]]></description><category>New Features</category><pubDate>Wed, 12 Aug 2026 07:02:54 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=924</guid><comments>https://bugs.xmbforum2.com/view.php?id=924#bugnotes</comments></item><item><title>0000923: Implicit Type Casting in Admin Forums Panel</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=923</link><description><![CDATA[I'm seeing an array key type mismatch here:&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;https://github.com/miqrogroove/xmb/blob/b1898487318785d25e28264a9a258fab58d48ded/admin/forums.php#L79&quot; rel=&quot;noopener&quot;&gt;https://github.com/miqrogroove/xmb/blob/b1898487318785d25e28264a9a258fab58d48ded/admin/forums.php#L79&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
PHP always performs an implicit type cast in this situation, but I don't want to rely on that behavior.]]></description><category>Bugs</category><pubDate>Wed, 12 Aug 2026 06:51:23 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=923</guid><comments>https://bugs.xmbforum2.com/view.php?id=923#bugnotes</comments></item><item><title>0000921: Provide Default Unit "px" For Theme Values</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=921</link><description><![CDATA[The deprecated HTML table attributes, such as cellpadding, used integer values without units, and are also compatible with string values including units.  CSS properties, on the other hand, are intolerant of missing units.  This makes the existing theme variables impossible to use in CSS if the theme developer never provided a unit with any numeric values.&lt;br /&gt;
&lt;br /&gt;
XMB needs to provide a valid default unit of &quot;px&quot; when the theme contains only a numeric value.]]></description><category>New Features</category><pubDate>Mon, 10 Aug 2026 10:37:27 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=921</guid><comments>https://bugs.xmbforum2.com/view.php?id=921#bugnotes</comments></item><item><title>0000916: Refactor All HTML Tables</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=916</link><description><![CDATA[All of the layout tables need to be replaced by CSS styles.&lt;br /&gt;
&lt;br /&gt;
This could become a component of a full refactor, but the tables represent a highly repetitive problem and it's a good starting place.]]></description><category>New Features</category><pubDate>Mon, 10 Aug 2026 07:13:56 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=916</guid><comments>https://bugs.xmbforum2.com/view.php?id=916#bugnotes</comments></item><item><title>0000920: Unclosed Element in Admin Search Results</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=920</link><description><![CDATA[The HTML strings generated by admin/search.php are missing the closing tags of some elements.]]></description><category>Bugs</category><pubDate>Sun, 09 Aug 2026 18:49:31 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=920</guid><comments>https://bugs.xmbforum2.com/view.php?id=920#bugnotes</comments></item><item><title>0000918: Wrong Link in Welcome Text</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=918</link><description><![CDATA[There is still a reference to cp.php hiding somewhere...&lt;br /&gt;
&lt;br /&gt;
I couldn't find it in the source code.  I believe this is an upgrade issue.  Previous versions wrote a setting named 'tickercontents' and v1.10 fails to upgrade that value to match the new URL structure.]]></description><category>Bugs</category><pubDate>Sat, 08 Aug 2026 16:09:00 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=918</guid><comments>https://bugs.xmbforum2.com/view.php?id=918#bugnotes</comments></item><item><title>0000833: "Your Personal Features" bar Should be Optional or Removed</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=833</link><description><![CDATA[The &quot;Your Personal Features&quot; bar really clutters up the front page and isn't very useful.]]></description><category>New Features</category><pubDate>Wed, 05 Aug 2026 08:35:28 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=833</guid><comments>https://bugs.xmbforum2.com/view.php?id=833#bugnotes</comments></item><item><title>0000917: WEBP file with JPG extension gets no thumbnail.</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=917</link><description><![CDATA[I uploaded a WEBP successfully with a .jpg extension in the filename, and it generated no errors and no thumbnail.&lt;br /&gt;
&lt;br /&gt;
Past versions of XMB never checked whether an image type recognized by GD was included in the filename extension filter, which caused some inconsistent behavior with newer type such as WEBP.]]></description><category>Bugs</category><pubDate>Wed, 29 Jul 2026 20:15:20 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=917</guid><comments>https://bugs.xmbforum2.com/view.php?id=917#bugnotes</comments></item><item><title>0000915: Move Template Start/End Comment Setting to Admin Panel</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=915</link><description><![CDATA[There is no reason to have the template &quot;$comment_output&quot; setting hidden in the config file.  Let's move it to the admin panel.]]></description><category>New Features</category><pubDate>Mon, 27 Jul 2026 16:20:20 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=915</guid><comments>https://bugs.xmbforum2.com/view.php?id=915#bugnotes</comments></item><item><title>0000912: "5 latest topics" on the stats page actually shows the last replies to the board</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=912</link><description><![CDATA[The heading implicates that it should be the last five threads that were created.&lt;br /&gt;
&lt;br /&gt;
However, it shows the last five threads in order of which they were replied to instead.&lt;br /&gt;
&lt;br /&gt;
This could be resolved via either adding the relevant SQL query and keeping the old one with a new heading, renaming the old one, or changing the query.&lt;br /&gt;
&lt;br /&gt;
(Making the stats page more useful would be quite nice, to be fair. There's probably some things I could think of.)]]></description><category>Bugs</category><pubDate>Mon, 27 Jul 2026 07:39:57 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=912</guid><comments>https://bugs.xmbforum2.com/view.php?id=912#bugnotes</comments></item><item><title>0000722: How to Mitigate TLS Inspection</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=722</link><description><![CDATA[TLS Inspection is a potential threat to all web servers and to any client not administered by the end user.  For example, the user of a computer at work or at a library might not realize the client's root trust list has been compromised.&lt;br /&gt;
&lt;br /&gt;
The result of a TLS Inspection deployment is that the TLS channel cannot be trusted at either end, and is effectively not confidential.  This exposes passwords, session cookies, and all other data on the wire.  Unfortunately, this is almost entirely beyond the control of the end user, and next to impossible to detect at the server.&lt;br /&gt;
&lt;br /&gt;
At the scripting level, almost nothing can be done short of redundantly implementing full asymmetric cryptography for both the client and server.  If the inspection threat is sufficiently malicious, then scripting solutions are moot because script itself can be compromised to defeat any form of trust.&lt;br /&gt;
&lt;br /&gt;
At the transport level, the obvious remedy is something like Apache's `SSLVerifyClient require` directive.  But this means a full PKI deployment to end users, just to protect confidentiality at the server level.  It also implies end users would be tied to their own devices or risk trying to use personal certificates on foreign clients.  To further complicate matters, the certificates would have to be tied to each user's account so that one user couldn't proxy traffic for another.&lt;br /&gt;
&lt;br /&gt;
This is a systemic risk to the whole Internet, but I am interested in any practical mitigation.]]></description><category>Research Tasks</category><pubDate>Mon, 27 Jul 2026 06:55:31 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=722</guid><comments>https://bugs.xmbforum2.com/view.php?id=722#bugnotes</comments></item><item><title>0000914: Session System Improvement</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=914</link><description><![CDATA[The XMB session subsystem has been expanded to allow easier extension beyond the default implementation.&lt;br /&gt;
- The session Mechanisms are now registered during XMB bootup, rather than hard coded inside the Session files.&lt;br /&gt;
- Login links are displayed only when a compatible Mechanism is registered.&lt;br /&gt;
- Logout links are displayed only when the current session has that capability.&lt;br /&gt;
- A proof of concept for an alternative Mechanism is provided in Certificates.php, which is not registered by default.&lt;br /&gt;
- BootupLoader::setVisit() moved to Login::setVisit() for consistent dependency structure.&lt;br /&gt;
- Core::getLoginLink() moved to Login::getLoginLink() for consistent dependency structure.]]></description><category>New Features</category><pubDate>Mon, 27 Jul 2026 06:54:46 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=914</guid><comments>https://bugs.xmbforum2.com/view.php?id=914#bugnotes</comments></item><item><title>0000889: Increase PHP Requirement to v8.4</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=889</link><description><![CDATA[We are already seeing dependencies like Symfony Mailer that no longer support PHP 8.2.  An increase of the PHP version should be considered.]]></description><category>New Features</category><pubDate>Wed, 15 Jul 2026 13:04:34 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=889</guid><comments>https://bugs.xmbforum2.com/view.php?id=889#bugnotes</comments></item><item><title>0000877: Update Symfony Mailer to v8</title><author></author><link>https://bugs.xmbforum2.com/view.php?id=877</link><description><![CDATA[Symfony 8.0 is available and should be updated for testing.]]></description><category>New Features</category><pubDate>Wed, 15 Jul 2026 13:04:34 -0700</pubDate><guid>https://bugs.xmbforum2.com/view.php?id=877</guid><comments>https://bugs.xmbforum2.com/view.php?id=877#bugnotes</comments></item></channel></rss>
