Yep, another site update! Two in two weeks is probably some kind of record for us. :P
Just a small one compared to the last, but with one major security improvement.
Changes for Revision 58
* Security: Updated our session IDs and form tokens to use sha512 hashes. sha512 generates longer values than the default md5 hashes. This makes it harder for attackers to simply guess valid session Ids and tokens. This may affect API users, so please read the full details here.
* API - Changed: Due to the above security update, the session ID (sid) transmitted to/from the API is now longer and can contain all alphanumeric characters, including capitals, and also the punctuation comma and dash. This may break some scripts that rely on the API and use authentication. Previously it could only contain hexadecimal characters in lower case.
* Added: You can now sort Unread Submissions in reverse date order (oldest first).
* Added: The user signup, password change and password reset pages now display a randomly generated password suggestion.
* Added: The user signup, password change and password reset pages now make it clear that a series of dictionary words is okay to use in a password, as long as the password isn't based on a single simple dictionary word.
* Changed: Usernames are now highlighted according to watch status when displaying them under icons and in reply box on Create New Private Message page.
* Fixed: Helper text like “Recipient Name...” in text entry boxes in various places like Create New Private Message page, or Member search page now clears correctly if the textbox is focussed by the keyboard via tab key or any other method which isn't the mouse.
* Added: When in “Search Gallery” mode, the Search page now shows a clear message right above the text entry box that you are searching within a specific user's gallery (also does this when searching within a user's favorites).
* Fixed: A bug in the search system prevented searches with odd punctuation that doesn't have a space after it from completing correctly. Eg: “my little pony:friendship is magic” would fail while “my little pony: friendship is magic” (with a space after the colon character) would work.
* Added: Automatic Twitter posts now add the Inkbunny name as a hashtag like #Inkbunny instead of just Inkbunny with no hash.