View Single Post
  #8  
Old 11-10-2017, 07:50 AM
 
Triple A Racing Triple A Racing is offline
 

X-Wizard
  
Join Date: Jul 2008
Location: Manchester UK
Posts: 1,028
 

Default Re: Did anyone notice PHP CLI xcart script

Quote:
Originally Posted by xim
....this tool is fully tested and ready to use for developers
That's fine, but the previous XC post "...this tool is still being tested" was different. You can see the inconsistency... Possibly more speed / less haste is needed.
Quote:
Originally Posted by xim
The full documentation is presented in kb here - http://devs.x-cart.com/misc/command_line_tool.html
It's a strange approach to have non-technical store owners (and there are many) being forced to wade through developers documents, simply to find our what they have been provided with, as part of a new upgrade... especially when they will never normally use these additions anyway. That's not normally the case elsewhere?
Quote:
Originally Posted by xim
About the security. It could be used only if you have access to the server. So, if a hacker has an access to the server, he doesn't need this utility to harm your store. However, we will implement the ability deny updating this file during the upgrade procedure. As a result, you will be able to remove this file forever
We didn't mention security. FWIW using a domain-name/xcart url will download the file by default... So if hackers were looking for clues, they're right there, but we do appreciate they do then need command line access to go further, so yours was good point, well made.
Quote:
Originally Posted by xim
We decided to include into the default package since it is more flexible for the developers, webmasters and our support team to use this toll instead downloading it separately.
This is the bit that's most irksome for us. Common sense and industry standards are being ignored here. XC5 should NOT be everything for everyone all rammed into one bloated package. Surely a normal set of different packages i.e. Free / Business / Multi Vendor / Ultimate / and then a separate specific Developer package which would add-on to Business / Multi Vendor / Ultimate packages is better, clearer, more accurate and more preferable for all? The size of our business packages has grown and grown and grown since we started with XC5, all it seems, for the convenience of XC, not us and/or any other 'normal package' paying customers? We do NOT want unfinished. non verified, still being tested developer tools being forced upon us by default (which has been the case several times now) unless of course we ask for them (^^^ see above) and... we certainly do NOT want all the ancillary files / processes and other clap trap of a Multi-Vendor package being forced upon us by default either, unless we have purchased that package by choice. Apologies if that sound harsh, but we need to say things exactly as they are, as opposed to being 'worried' about any fallout. We've stated several times that we are big XC5 supporters (we still are and still happy that we switched from XC4) but it's currently feeling (for us anyway) quite disjointed, inconsistent, confusing, unclear and just plain random sometimes to be fair. In fairness, we'll re-visit that line after upgrading to XC 5.3.3.5 then XC 5.3.4.*
__________________
Dev Store & Live Store XC Business 5.4.1.35
Server; Ubuntu 22.04.2 LTS (HWE 6.2.0.26.26 Kernel)) / Plesk Obsidian
Nginx 1.20.4 / Apache 2.4.52 (Ubuntu Backported) / MariaDB 10.11.4 / PHP 7.4.33
Reply With Quote