<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SnowCMS &#187; snowcms</title>
	<atom:link href="http://www.snowcms.com/tag/snowcms/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.snowcms.com</link>
	<description>It snows here...a lot.</description>
	<lastBuildDate>Sun, 20 Jun 2010 05:47:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Now we really are getting close!</title>
		<link>http://www.snowcms.com/now-we-really-are-getting-close-77/</link>
		<comments>http://www.snowcms.com/now-we-really-are-getting-close-77/#comments</comments>
		<pubDate>Sun, 20 Jun 2010 05:47:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News and updates]]></category>
		<category><![CDATA[snowcms]]></category>

		<guid isPermaLink="false">http://www.snowcms.com/?p=77</guid>
		<description><![CDATA[As of last night, I have committed r991, which completes plugin management. That means now plugins can be installed, uninstalled, enabled, disabled and updated&#8230; Something I have been waiting to complete for quite some time So now we are really close! I hope to have an alpha release soon&#8230; You can always discuss at the [...]]]></description>
			<content:encoded><![CDATA[<p>As of last night, I have committed <a href="http://code.google.com/p/snowcms/source/detail?r=991" title="revision 991" target="_blank">r991</a>, which completes plugin management. That means now plugins can be installed, uninstalled, enabled, disabled and updated&#8230; Something I have been waiting to complete for quite some time <img src='http://www.snowcms.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>So now we are really close! I hope to have an alpha release soon&#8230; You can always discuss at the <a href="http://dev.snowcms.com/" target="_blank">SnowCMS Dev Forum</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.snowcms.com/now-we-really-are-getting-close-77/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sorry about the lack of new posts!</title>
		<link>http://www.snowcms.com/sorry-about-the-lack-of-new-posts-53/</link>
		<comments>http://www.snowcms.com/sorry-about-the-lack-of-new-posts-53/#comments</comments>
		<pubDate>Sun, 31 Jan 2010 08:16:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Developer updates]]></category>
		<category><![CDATA[News and updates]]></category>
		<category><![CDATA[developers]]></category>
		<category><![CDATA[development]]></category>
		<category><![CDATA[plugins]]></category>
		<category><![CDATA[snowcms]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.snowcms.com/?p=53</guid>
		<description><![CDATA[I apologize for the lack of posts lately. I have yet to post anymore tutorials on how to use some of SnowCMS&#8217;s tools, like how I did with the API class. But don&#8217;t worry, although I have not been that active posting here, I have been fairly busy working on SnowCMS. I recently completed a [...]]]></description>
			<content:encoded><![CDATA[<p>I apologize for the lack of posts lately. I have yet to post anymore tutorials on how to use some of SnowCMS&#8217;s tools, like how I did with the <a href="http://www.snowcms.com/it-has-been-awhile-43/" target="_blank">API class</a>. But don&#8217;t worry, although I have not been that active posting here, I have been fairly busy working on SnowCMS.</p>
<p>I recently completed a new tool for SnowCMS, the <a href="http://snowcms.googlecode.com/svn/docs/files/core/form-class-php.html" target="_blank">Form class</a>. The Form class allows you to create forms (if you didn&#8217;t notice) that can then be hooked into via the API and changed, without you needing to do any extra effort, you simply make the Form how you want to, and then display it. Right before the form is displayed (or processed), the API runs a hook which allows the modification of the form, from adding, changing and removing fields. In fact, currently the registration form uses this Form class, and the very first SnowCMS plugin hooks into the form and adds a CAPTCHA verification image. It&#8217;s very simple to do!</p>
<p>For the time being, I need to get some sleep (it is 12:15AM at the time of this post), but I hope to soon create a more in depth guide to the creation of forms using the Form class.</p>
<p>Cya soon!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.snowcms.com/sorry-about-the-lack-of-new-posts-53/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Keeping your credentials secure</title>
		<link>http://www.snowcms.com/keeping-your-credentials-secure-49/</link>
		<comments>http://www.snowcms.com/keeping-your-credentials-secure-49/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 18:15:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Developer updates]]></category>
		<category><![CDATA[developer]]></category>
		<category><![CDATA[development]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[snowcms]]></category>

		<guid isPermaLink="false">http://www.snowcms.com/?p=49</guid>
		<description><![CDATA[One big goal of SnowCMS is providing a secure system, but of course, who wouldn&#8217;t want that? In order to keep that system secure, user credentials also need to be kept secure, because if someone gets a hold of that information, especially of a member who has powers, your site would likely become compromised. So [...]]]></description>
			<content:encoded><![CDATA[<p>One big goal of SnowCMS is providing a secure system, but of course, who wouldn&#8217;t want that? In order to keep that system secure, user credentials also need to be kept secure, because if someone gets a hold of that information, especially of a member who has powers, your site would likely become compromised.</p>
<p>So how do we keep your password secure? For starters, the password kept in the members database is salted with your username and then encrypted using SHA1. By salting your password, it helps prevent the use of rainbow tables (You know, those sites that have databases with plain text strings and their encrypted counterpart). Then there is logging in, when you submit your credentials through the log in form, your password gets salted with your supplied username, hashed using SHA1, then salted with a randomly generated string which is done by the server. Your plain text password is deleted before the form is sent to the server. Now, this only will occur if you have JavaScript enabled, of course. Once the hashed password is sent to the server, it takes out your members row, and salts (The last salt generated) the hashed password in the database and hashes it, then compares it to the one received from you. If they match, that means your password is correct.</p>
<p>Securing your password before being sent to the server might seem a bit overkill, but it can be very useful. As you never know, someone could be logging POST data, which would contain your log in credentials. All they would get would be your encrypted password which is salted with a randomly generated string. The only way they could <em>ever</em> use that password to log in to your account would be if the server were to generate the same random string, which is highly unlikely.</p>
<p>There are two ways that SnowCMS keeps your password from ever being seen by human eyes, but there is still one more. Cookies! No, not those kind, the Internet kind. With every page load, your browser sends the cookies to the server, where they can then be used to identify whether or not you are logged in. Instead of sending your password just with your username salting the password, there is also a randomly generated hash in the database that salts your password in the cookie&#8230; Just in case <img src='http://www.snowcms.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Not all people have access to SSL, which would stop such possible attacks, which is why we at SnowCMS have decided to use such tactics to protect not only the system itself from security issues, but also the people who use our system as well.</p>
<p>Just a reminder, the <a title="SnowCMS Dev Forum" href="http://dev.snowcms.com/" target="_blank">SnowCMS Dev Forum</a> is now open to the public, if you are interested in having part in the development, or just like to see what is happening, you should come and join us.</p>
<p>Till next time, cya!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.snowcms.com/keeping-your-credentials-secure-49/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lots of pondering going on</title>
		<link>http://www.snowcms.com/lots-of-pondering-going-on-23/</link>
		<comments>http://www.snowcms.com/lots-of-pondering-going-on-23/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 04:24:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Developer updates]]></category>
		<category><![CDATA[bbc]]></category>
		<category><![CDATA[bbcode]]></category>
		<category><![CDATA[flakes]]></category>
		<category><![CDATA[mod system]]></category>
		<category><![CDATA[snowcms]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[updating]]></category>

		<guid isPermaLink="false">http://www.snowcms.com/?p=23</guid>
		<description><![CDATA[Right now Myles and I are pondering about quite a few things to put into SnowCMS. Mod system Of course SnowCMS will have a modification system, and the dev team and I were thinking about how to do it. Some systems have a sort of API system, where basically every so often, the system will [...]]]></description>
			<content:encoded><![CDATA[<p>Right now Myles and I are pondering about quite a few things to put into SnowCMS.</p>
<p><strong>Mod system</strong><br />
Of course SnowCMS will have a modification system, and the dev team and I were thinking about how to do it. Some systems have a sort of API system, where basically every so often, the system will call on some kind of hooks are integrated for developers to latch on to. But there is not much power. Sure it would be simple for use to make, and then updating SnowCMS powered sites would be a snap, we don&#8217;t want to take the easy way out <img src='http://www.snowcms.com/wp-includes/images/smilies/icon_razz.gif' alt=':-P' class='wp-smiley' /> </p>
<p>Other systems allow you to modify all the files themselves. It can be a little more complicated, but it also poses a threat to users if they were to install malicious modifications. Probably pretty unlikely, but hey! It can happen&#8230;</p>
<p>Another way is super easy. Not having one at all. Of course, we wouldn&#8217;t do that. We have come to a unanimous decision to have file based editing for the modification system. Oh, and did I mention modifications are referred to as &#8216;flakes&#8217;?</p>
<p><strong>Mod security</strong><br />
As I mentioned about allowing people to modify the sources of the system can be dangerous. So how are we as developers going to combat that?</p>
<p>Pretty simple, well, at least simple in concept. What will happen is people will be able to submit modifications to our site (Eventually we will have a modifications database, of course!) and once the team has reviewed it (Either developers, or maybe a modification team) and approved the modification to be done well and doesn&#8217;t do anything bad, the file will have its hash taken (SHA-1, most likely) and stored in a publically accessible way (In a database and can have the data retrieved). Now once the modification is uploaded to your site, and once your about to install it, your system will hash the file and send it off to SnowCMS.com. We (well, the server&#8230;) will then take that hash and check to see if it exists and is approved in our database. If it is, you will see a message saying the modification is safe and has been approved by the SnowCMS team.</p>
<p>A pretty good idea. Because if that modification which you uploaded to your site was changed in any way, it won&#8217;t be in our database. Simple, but darn effective =P.</p>
<p><strong>Updating</strong><br />
Since SnowCMS will feature a modification (flake) system, updating will be pretty straight forward. Once SnowCMS goes gold, whenever an update is out (Like 1.0.1) we will have those updates put into a flake package. That way even when you have modifications installed, you should be able to update pretty easily with little to no errors. But of course, in the beta and RC stage, you will not be able to update via this system due to the major amount of code changes that will occur. Sorry!</p>
<p><strong>BBCode</strong><br />
Like I talked about in previous posts, I certainly hope by either public beta release or when 1.0 goes gold, we will have the new BBCode parser complete. Still working on it.</p>
<p>Well, a lot of information about SnowCMS v1.0. Until next time, see ya! XD.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.snowcms.com/lots-of-pondering-going-on-23/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Topic posting complete</title>
		<link>http://www.snowcms.com/topic-posting-complete-18/</link>
		<comments>http://www.snowcms.com/topic-posting-complete-18/#comments</comments>
		<pubDate>Thu, 16 Jul 2009 06:10:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News and updates]]></category>
		<category><![CDATA[bbc]]></category>
		<category><![CDATA[bbcode]]></category>
		<category><![CDATA[development]]></category>
		<category><![CDATA[forum]]></category>
		<category><![CDATA[posting]]></category>
		<category><![CDATA[snowcms]]></category>
		<category><![CDATA[topics]]></category>

		<guid isPermaLink="false">http://www.snowcms.com/?p=18</guid>
		<description><![CDATA[Today I worked quite a bit, and I finally got topic posting completed and working without errors Still no replying or editing done yet, but I am working on it! And about the BBCode, I still haven&#8217;t completely finished it, but it is almost there XD.]]></description>
			<content:encoded><![CDATA[<p>Today I worked quite a bit, and I finally got topic posting completed and working without errors <img src='http://www.snowcms.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  Still no replying or editing done yet, but I am working on it!</p>
<p>And about the BBCode, I still haven&#8217;t completely finished it, but it is almost there XD.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.snowcms.com/topic-posting-complete-18/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
