webCOMAND 3.11 Released
The webCOMAND Sign In and Users Framework now support fully custom Multi-Factor Authentication to improve security for your webCOMAND instance, website and/or apps.
Multi-Factor Authentication (MFA)
Features include:
- Email and/or SMS (Text Message) - Users can chose email and/or SMS MFA each time they login.
- Custom Requirements - Each Login Policy may require for:
- All users
- Only select users
- All except select users
- No users
- Custom Thresholds - Adjust the number of allowed attempts by time period, IP address and/or User Agent.
- Custom SMS Service - Supports custom Twilio account, and extensible to other SMS services.
- Custom Templates - Customize the MFA email and text message.
- Custom Codes - Specify the code length and number of minutes they are valid.
Additional Updates
- New requires_store(), requires_save() and requires_approve() cObject methods allow developers to customize when objects and their embedded children are approved, even if they have not been modified.
- Fixed when a user pastes a copied object, their user information is associated with the update in the version history, instead of the admin user.
Subsequent Minor Updates
webCOMAND 3.11.1 (Oct 14, 2025)
- Web Socket Server - Several improvements to the Web Socket Server driving dynamic Content Manager functionality. Performance improvements were made to speed up connections listening to running tasks by non-super users, and a dedicated task listener was introduced which replaces less efficient cPaths for certain operations. The Web Socket Server was also updated to respond to changes to the underlying type caches and to users and user roles/privileges. In addition, configurable logging functionality was introduced with periodic status reports to aid in troubleshooting and performance improvements in the future.
- Map View - Improve the default zoom level to be more appropriate when there is only one visible coordinate, or when several coordinates are located very close together.
- Web Launcher - Add configurable PHP file extensions to determine which file extensions the web_launcher will process as PHP code.
- Publication Framework - Add tracking of all published files to the Publication object at publish runtime. Also add Publication content type method stubs: PublishedObject(), PublishedProcedure(), Published().
- Sites Framework - Fix missing "$HTML +=" before insert() in Navigation template, and fix where ParentPageOID was incorrectly referenced instead of ParentPageDOID.
- Backup / Restore - Fix CMS backup filename issue that prevented restore of very large data tables.
- Email API - Fix IMAP email processor catch an exception when converting a message to UTF-8, and instead fallback to the detected encoding if the declared encoding in the email is not supported by PHP.
- Grid View - Update the grid view to handle presenting decimals
- Navigation Bar - Fix potential null exception when rendering certain types of cpath view title bars when the cpath is empty.
webCOMAND 3.11.2 (Nov 12, 2025)
- cQL STRCMP() - Add string comparison function to cQL.
- Publication Settings
- Add All Publication Procedures and All Publications check boxes to explicitly specify when all procedures and/or publications should publish. Previously this was configured by not selecting a procedure or publication, but that could easily be configured by mistake when a previously configured procedure or publication were deleted. This update prevents that mistake from happening.
- Add Folder Context Only check box to only apply settings when the user opens the target object(s) in the context of the selected Folders. This also applies to Search Settings, View Settings and Rich Text Settings.
- Fix issue in publishing content with multiple settings tied to the same publication.
- Fix issue in the publishing sidebar when viewing an embedded object.
- System Tasks - Fix issue that prevented events from logging to a System Task after it was cancelled.
webCOMAND 3.11.3 (Nov 24, 2025)
- Panel - Add option for developers to disable Search Settings.
- PHP API Web Client - Add PATCH request support.
- Diagnose - Separate slow query thresholds into separate settings for clean, repair, and optimize.
- UI Methods - New feature to add custom buttons to the Form View toolbar per content type.
webCOMAND 3.11.4 (Nov 25, 2025)
- Fix content cache to clear cached fields by DOID as well as by OID when content is approved.
webCOMAND 3.11.5 (Dec 1, 2025)
- #META - Add cTemplate directive to access repository object metadata.
- #CLONE - Add cTemplate directive to return a shallow-clone of objects and arrays.
webCOMAND 3.11.6 (Dec 8, 2025)
- cScript Custom Functions can now be redefined during a publish process.
webCOMAND 3.11.7 (Dec 16, 2025)
- Add Cleanup Publication Records Scheduled Task to identify and delete Publication Records associated with deleted Publications, Procedures and Objects, as well as those added incidentally during a publish.
webCOMAND 3.11.8 (Jan 8, 2026)
- Add PHP File Validation to prevent writing and publishing PHP files with invalid syntax.
- Retired the class loader Safe Include feature in lieu of PHP File Validation.
webCOMAND 3.11.9 (Feb 11, 2026)
- Update Revert to Last Approved to better handle variants. Avoid inadvertently deleting variants when there are unapproved variants to be deleted. Better handle embedded records with variants by matching revert actions to the most relevant variants.
- Add Archive File Extractor Content Type to make it easier to extract, write and publish archives based on rules.
- Improve Grid Editor formatting support for plain text fields.
- Improve load_config() to discover and merge the config at all package paths in reverse order, instead of just using the first encountered.
- Fix CSS Minify issue that removed critical whitespace from before a colon (e.g. :first-child) in some cases.
- Add cMVC Router base_dirs option to configure the router to look in multiple cascading folders for views and public files. Also no longer add the namespace_path or base_dir as a namespace path if the namespace_path router option is set to FALSE to find controllers in all package folders.
- Improve Import to add content logs when content is updated from import data.
- Fix Restore to correctly write BinaryValue values in field tables.
- Fix e-commerce promotions to ensure they are accurate on shopping cart update.
webCOMAND 3.11.10 (Mar 13, 2026)
- Fix User Authorizations issue that prevented authorized users from deleting a single object variant.
- Improve Grid Editor to disable drag mode while editing a cell.
- Update csv util methods to make options optional.
- Fix Sites Framework List Component HTML cTemplate to consider each list item's Status.
webCOMAND 3.11.11 (Mar 31, 2026)
- Update Forms Framework to support for multiple challenges and a new Authorize.net challenge type.
- Improve Archive File Extractor Content Type with new Write Archive, Extract Archive, Log Extraction Details and Destination Link options.
- Improve Import/Export to support multi-variant content, which also enables multi-variant support for Pull Settings.
- Improve #LINK error reporting when deleted or disabled content is referenced.
- Add cQL MD5() function.
- Improve Object Cache memory management to invoke memory checks at more points in field loading and writing.
- Fix Repository to regenerate types cache correctly if an issue is found.
webCOMAND 3.11.12 (May 7, 2026)
- Packages Write Files - Write files to file system path that mirrors the repository subfolder hierarchy within a package.
- Number Field Type - Decimal and Currency Data Type validations now allow a leading decimal (.2 means 0.2).
- Content Types - Add validation to ensure that a Content Type's Extends field is set.
- COMAND Help - Add tabs to better organize Help Docs and it's sub-types.
- Search Settings - Allow a SELECT clause for the given cPath to take precedence over any selected fields in the Search Settings Filter.
- Export Settings - Update SELECT order precedence when exporting content from webCOMAND. Fields defined in selected Export Settings will take precedence over cPath SELECT statements or selected Search Settings.
- #IMAGE - Fix issue where Imagick setFormat wasn't being properly applied (force change on current frame).
- Form View - Optimize stats queries by removing dimensional queries to boost performance and reduce server load.
- Form View - Fix cancel action to not also cancel the reordering of the cancelled item within its parent folder, which is managed separately from the parent collection view.
webCOMAND 3.11.13 (May 21, 2026)
- COMAND Email - Log more details at appropriate log levels when low-level mail errors are encountered.
- Rich Text Settings - Add Publications and Procedures options to improve link dialog usability with faster link search and more relevant search results.
- Sites Framework - Moved all Page logic to SitesPage.HTML cTemplate, so it can be overridden without having to modify the Page Publication Procedure and fixed logic to avoid publishing pages with Do Not Open checked.
- cMVC Framework - Update cMVC router to quietly ignore extra parameters in the path that don't have corresponding method parameters, rather than logging a PHP warning about referencing an undefined array index.
- Query Class - Add 'Communication link failure' as a recoverable database connection error, and like similar errors, attempt to reconnect and retry the query automatically.
webCOMAND 3.11.14 (Jun 4, 2026)
- Users Framework - Add "Include Success" option to Login Attempt Thresholds to throttle actions with no failure condition, improve security notification emails, and report usernames to Login Security Logs during the create user workflow.
- Email Framework - Update Email content type's Attachments field to allow multiple attachments with the same Filename, which is allowed by the email spec.
webCOMAND 3.11.15 (Sep 2, 2026)
- Image Processing API - Add automatic fix for certain types of images with corrupted or unexpected metadata. Add object and field information to ImageData when loaded from the repository to improve unrecoverable image errors.
- #TEXT - Add EscapePHPStringSingle and EscapePHPStringDouble for specific escaped versions. EscapePHPString will continue to escape both types of quotes for backward compatibility.
- #TEXT - Add EscapeJSONString option that is similar to EscapeJavaScriptString, but it does not escape single quotes to comply with strict JSON rules.
- Session Class - Improve how sessions and session profiles are managed to reduce the number of session files.
- No longer add empty session files, and close the gap to unset session keys in the written session file when they are unset programmatically in the in-memory session data.
- No longer add a session on read if they don't already exist.
- Destroy old session files when regenerating session IDs.
- Fix issue that prevented regenerated session IDs from being written to the browser cookie.
- Fix open and write to multiple sessions within the same PHP process.
- Streamline session profile garbage collection and make more memory efficient when there are very large numbers of session files to review.
- Session profiles now permit custom garbage collection rules that enable different maxlifetimes based on key/value pairs within stored session data.
- Cleanup Repository - Add rules to clean up older webCOMAND system files that are no longer needed.
- File Framework - Add \io_comand_file\util::visit() to handle large and deep folder structures more efficiently.
- File Framework - Fix E_DEPRECATED warning when using memfiles as a registered stream wrapper.
- Scheduled Task - Update System Tasks to send an email by default when they time out. Fix retried System Tasks to have the same Timeout values as the original System Task.
- Email Content Type - Update Email Queue clean up process to handle gaps and batch delete to improve efficiency.
- Repository CLI - Add archive_info to get CMS and MySQLDump archive details.
- Repository CLI - Improve diagnose warnings when working flag issues cannot be repaired.
- Batch Edit - Allow batch editing of relative forward reference fields.
- cObject Model - Add requires_write(), before_write() and after_write() callbacks for logic shared by all write actions.
- Event Logger - Fix PHP warnings where floats were implicitly converted to ints when logged events were rendered.
- Update form template to handle Choices cPaths properly and render as select dropdown options.
- cMVC Framework - Fix router::view() to load correct view when multiple base_dirs were configured for the router.
- COMAND PHP API - Fix comand::connect() to not reuse an existing connection opened in a different mode.
- Content Type Editor View - Fix to automatically add content to a field location folder when the field is marked as Allow Add and "Choose related from:" is a cPath that evaluates to multiple results, as long as exactly one result is a Folder.
- cTemplate / cScript - Add #ABS, #CEIL, #EXP, #POW, #SQRT and optional second parameter to #ROUND.
webCOMAND 3.11.16 (Sep 8, 2026)
- Scheduled Tasks - Add new indexes to key repository tables to speed up various repository Scheduled Tasks.
- Workflow Menu - Fix "Revert to Last Approved" for a draft that overlapped a snapshot or revision lock.
webCOMAND 3.11.17 (Sep 28, 2026)
- Web Services - Add Archives Web Service that can list and serve archive files to authorized users from a webCOMAND instance.
- Repositories App - Improve the restore process better handle when the repository is re-written as part of the process.
- Improve maintenance mode handling within the daemon processor. Prevent kicking off new scheduled tasks when the system is in maintenance mode, and improve the output of the daemon status check to reflect this.
- Repositories App - Improve the write files runnable that happens after a restore to report more information on its status.
- Model - Improve performance of field identifier changes on very large data sets to reduce mutation times.
- Model - Fix when a relationship field that overrides a data field is removed or updated with a new field identifier, original data associated with the overridden data field that is still in the repository will become accessible again.
- Scheduled Tasks - Improve Diagnose Repository to update the character set to utf8mb4 to better support 4-byte UTF8 encoding, and to catch all possible Folder OID discrepancies for a particular content type.
- Scheduled Tasks - Add better handling of task event results and logging to the SystemTask.
- Scheduled Tasks - Update comand to maintain the task under which the process is running if applicable, rather than all repository connections maintaining this separately.
- Scheduled Tasks - Deprecate CLI Runnables for core repo maintenance tasks and replace with PHP Runnables that are more efficient and more easily maintained.
- System Tasks - Report an error when a System Task has no Runnables, or has a PHP Runnable that does not map to a class that can be loaded at runtime.
- System Tasks - Fix cyclical error and exception handling related to repository update or connection failures.
- File Framework - Fix chown(), chmod(), and delete() to allow access outside of narrowly designated folders when appropriate.
- Simple UI Framework - Simplify common CLI tools now that they no longer run under CLIRunnables
- Event Logger - Fix event logs to prevent log cycles if the same logs are joined in the chain of relay logs.
- Event Logger - Deprecate system/tmp/debug_log. All logging now goes to files under files/logs/webcomand.
- Repositories - Fix folder re-cache feature to respect temporary state when invoking the types cache.
- Diagnose - Improve character set and collation detection to avoid schema updates when they're not required.
More Posts
May 5, 2025
webCOMAND 3.10.0 Released
webCOMAND 3.10.0 improves Grid View, storage efficiency and content retention options.
June 12, 2024
webCOMAND 3.9.0 Released
webCOMAND 3.9.0 improves the user interface and save performance.
November 3, 2023
webCOMAND 3.8.0 Released
webCOMAND 3.8.0 improves email features, CSV import/export and API authorization options.