Top.Mail.Ru
  • CMS «GIRVAS»

    A flexible and free content management system that allows you to create a website of any direction.

    It's easier with us!

  • Absolutely free

    Stop using old and paid management systems! The era of new solutions has come - choose «GIRVAS»!

  • Karelian solution

    CMS "GIRVAS" was developed in the Republic of Karelia and is also included in the Register of Russian software by the Ministry of Digital Development of the Russian Federation (registry entry No. 25012 dated 11/27/2024).

0.4.0 “Segezha”

Release of CMS “GIRVAS” dated October 3, 2026, at the “Segezha” development stage.

Latest Changes

QueryBuilder: JOIN, CASE expression, and index support

Implemented:

  • Added the IndexType Enum with index types (BTREE, HASH, GIST, GIN, SPGIST, BRIN, FULLTEXT)
  • Added the ClauseJoin class for JOINs in SELECT (INNER, LEFT, RIGHT, FULL)
  • Implemented adaptive generation of JOIN conditions for MySQL and PostgreSQL
  • Added the CaseExpression class for building CASE expressions
  • Implemented the whenJsonLike() and whenJsonArrayContains() methods for JSON search
  • Added the static method CaseExpression::sum()
  • Added the factory method createCase() in QueryBuilder
  • Added the StatementCreateIndex class for CREATE INDEX
  • Added the StatementDropIndex class for DROP INDEX
  • Implemented support for UNIQUE, CONCURRENTLY, IF NOT EXISTS/IF EXISTS, and partial indexes with WHERE
  • Added the setStatementCreateIndex() and setStatementDropIndex() methods
  • Added caching of initialized data in EntryCategory

Fixed:

  • Escaping of CASE expressions in addSelections() for PostgreSQL

SQL dialects: MySQL and PostgreSQL support at the core level

Implemented:

  • Abstract class Dialect and implementations PostgreSql, MySql
  • DialectFactory factory
  • Logical types (id, bigint, integer, boolean, string, string:N, text, json, timestamp)
  • JSON methods (jsonExtractBoolean, jsonExtractInt, jsonBuildObject, jsonMergePatch, jsonMergePatches, jsonObjectMergeKey, jsonLike, jsonArrayContainsLike)
  • Date methods (extractYearFromUnixTimestamp, extractMonthFromUnixTimestamp)
  • LIKE, IN, LIMIT/OFFSET, getLastInsertedIDCondition methods
  • Capability methods (supportsInsertReturning, supportsConcurrently, supportsIfNotExistsForIndex, supportsPartialIndex, supportsDropIndexConcurrently, supportsDropIndexIfExists, supportsIndexType, requiresUsingClause, supportsDefault)
  • All Statements migrated to the dialect (CreateTable, CreateIndex, DropIndex, Insert, Select, Update, Delete)
  • All Clauses migrated to the dialect (Returning, From, Join, Where, OrderBy, Limit, Set)
  • Installer adapted: 22 tables, 64 indexes, createIndexSafe()
  • Business logic migrated to the dialect (13 files: Entry, Entries, EntryCategory, EntriesCategories, EntryComment, EntryComments, User, Users, UserGroup, UsersGroups, PageStatic, PageStatic/Version, Pages)

152-FZ: full technical coverage at the core level

Implemented:

  • Logging of all actions involving personal data (entries, pages, media, users, categories, selections, forms, blocks, comments, groups, feeds, CMS settings)
  • Logging of access to personal data (user card, user list, another user"s profile, login/logout, form submission, viewing logs, list of consents)
  • Logging of CMS settings with recording of only actually changed fields
  • Versioning of legal documents (pages_static_versions table, PageStatic\Version class, administrative panel UI, reading ?version=X.Y on the frontend)
  • Recording of consents in dynamic forms (User\Consent class, consent field type, binding to document and version)
  • Recording of consents during registration (UserConsent::giveBatch)
  • Withdrawal of consent in the user profile (api/user/patch.handler.php handler, “My Consents” UI)
  • Viewing and managing consents in the administrative panel (/admin/usersConsents, PERMISSION_ADMIN_USERS_CONSENTS_MANAGEMENT permission)
  • CSV export of consents (14 columns, BOM for Excel)
  • Export of data subject data under Art. 14 (ZIP: profile.json, consents.csv, reports.csv, manifest.json)
  • Protection against IP address spoofing (Client::getRealIPAddress, trusted proxies, IPv4/IPv6 CIDR check)
  • Anonymization of personal data under Art. 5 (User\Anonymizer class, User::isAnonymized, /handler/user/anonymize handler)
  • Log rotation under Art. 5 (reports_archive table, Reports\Rotator class, cron/rotateReports.php, UI at /admin/settings/security)
  • Cookie banner for all visitors (including anonymous users) with consent recording and duplicate protection
  • security_legal_documents setting in the administrative panel (selection of legal documents)
  • Multilingual reports (entryTitles, pageTitles, categoryTitles, etc. by locale)

OAuth provider: server side

Implemented:

  • Three tables: oauth_clients, oauth_auth_codes, oauth_access_tokens
  • Client, AuthCode, Token classes in core/PHPLibrary/OAuth/
  • Endpoints /handler/oauth/authorize (GET/POST) and /handler/oauth/token (POST)
  • Support for authorization_code and refresh_token grants
  • Mandatory PKCE support (S256)
  • Strict redirect_uri validation (exact match, prohibition of non-HTTP schemes)
  • One-time authorization codes with a 60-second TTL
  • Refresh token rotation on every refresh
  • client_secret hashing via BCrypt (cost=12)
  • Client verification by an administrator before granting access
  • Limits on the number of tokens per application
  • Exclusion of CSRF verification for /handler/oauth/* (protocol requirement)
  • CLI test oauth_test.php (11 checks) and HTTP test oauth_http_test.sh (full cycle)

Fixed:

  • RegenerateSecret() did not save the new secret
  • Empty scope on refresh token

Multilingual website settings

Implemented:

  • JSON storage of settings by locale (base_site_title, seo_site_description, seo_site_keywords)
  • Helpers getAdminLocaleName and getLocalizedSettingValue
  • Support for three read formats: new JSON, old flat list, old flat string
  • Automatic migration of old data on first save
  • Separation of admin and public locale (Configurator::getSiteTitle/Description/Keywords)
  • UI: locale select in the settings page header, hidden _settings_locale field

Fixed:

  • Bug with “Array” output in the title/description/keywords after the first save
  • Bug with a rare inability to retrieve locale data

Automatic index creation during CMS installation

Implemented:

  • Added an index creation block at installation step 6 after table generation
  • Indexes for the entries, entries_categories, entries_comments, pages_static tables
  • Indexes for the users, users_sessions, forms_data, web_channels, metrics tables
  • Unique indexes on name, login, email
  • For PostgreSQL, GIN indexes on JSONB fields and a partial index for published entries were added
  • All indexes are created with IF NOT EXISTS; errors are logged without interrupting installation

Administrative panel: search and sorting

Implemented:

  • Search and sorting in 10 sections: users, usersGroups, usersConsents, entries, pages, entriesCategories, entriesComments, entriesSamples, forms, contentBlocks
  • GET parameters ?value=... and ?sort=... from a whitelist
  • Preservation of parameters in pagination (buildQueryString + startPart)
  • UI: Choices + Input + Button in the #E8548530785 container
  • getAll($searchValue, $sortRule) and getCountTotal($searchValue) methods in repositories
  • 6 sorting rules (by creation/update date ↑↓, alphabetically ↑↓)

Fixed:

  • Users::getCountByGroupID() bug — extra AND in the MySQL branch
  • Adaptive column quoting for PostgreSQL

Yandex.Metrica

Implemented:

  • seo_code_yandex_metrika setting (numeric ID only)
  • Field at /admin/settings/seo
  • Insertion of the Metrica script and <noscript> into <head> (theme default)
  • Double validation: preg_replace("/\D/", "") on save, ctype_digit() on output
  • Insertion via createTextNode + appendChild (otherwise saveHTML() breaks the inline script)

Other

Fixed:

  • Cookie banner was shown again when the allowCookies cookie was present
  • Batch insert on MySQL with innodb_autoinc_lock_mode = 2
  • Leakage of sensitive fields in debug output

Previous release: 0.3.0 “Shuya”

Translations

Comments

There are no comments for this entry.