\FF\D8\FF\E0\00JFIF\00\00\00d\00d\00\00\FF\FE\00\border bs:0 bc:#000000 ps:0 pc:#ffffff es:0 ec:#000000 ck:feee6c715d26fd9f38b0ca4278c05026\FF\DB\00C\00P7<F<2PFAFZUP_xxnnx\F5\AF\B9\91\C8\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\DB\00CUZZxix‚\EB\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\C0\00\00b\00d\00\FF\C4\00\00\00\00\00\00\00\00\00\00\00\00\00\00\FF\C4\00\00\00\00\00\00\00\00\00\00\001A!Q\FF\C4\00\00\00\00\00\00\00\00\00\00\00\00\00\FF\C4\00\00\00\00\00\00\00\00\00\00!1AQ\FF\DA\00\00\00?\00\F6\00\00\00\00\00\00\00\00\00\00\A0\00\00\C5\CF\F8\E7Ó\FCjD~\B9^\AD\%\B3]\D8cs-\BBs,-\A0\00"\80\00%\B83rÏ^K~F\A4ea\00E\00\C6\EE=u\B1\9B\D1\00@\00r\BE8\F9:\FE5#.M\00\E7\CB\C9q\CBq\D6\F2\BE\B7\C7>\C9n5×\D6?\BDê\9Ds\EBp\9F[`8m\B7)o\B5\E8\E6I\99\FE3]]A2\BA\8Cw\D6E\93\\DEv\C8\009\F2\F1NI?uc\\F5\EA\96k\xN<~buv\EA\C8\D7	\8B\84\CEcxI\BBg\AE\9E=\D6+n\EC\80\C8A\8C\AE\EB\CF\D5\DA\E9"2\A4\B9j5\EB\F3W\B63\96\B30Yu\DA\FC8\ED\DF\E7Ms\FB\F1\8E\B3\FA\EA\E8\E6(\883zs\F2_\8DFk\8Bh
\00\8C\DCw\D3R\B5+6X\BA\B2\C4j\AB0\B4\FCMw\C2I\8E\9B\E3\A9~9u\FA\D3l\80\C8%p\EE\FDn2€
\00$\FEj\C4e\A9\DB\~\95\A7\A5\80EK\BB\8DDsP\00@@AD'k\CF\E8\DB\D2(\80\9AK\D3\85\D6lb\F2\BA\8C*\80\00)\95
59\A3R:\F3\CE"\B6\80\88\00\00i1u4ê\E9\F2á\A6\A2\FACM\93WMb*\E0*\00\00\00\00\00(\A8\80\00\00\80\00\00\00\00\00\00\00\00\00\FF\D9<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <meta name="viewport" content="width=device-width, initial-scale=1.0">
    <title>C///</title>
</head>
## [v2.7.3] - 2026-08-24

### Bug Fixes
- **xswatch5**: Align the inner pagination guards with the outer one
- **xswatch5**: Guard the optional search values in the theme override
- **search**: Cast the required row fields to string in the normaliser
- **search**: Write the row uid back to the row in the show-all loop
- **browse**: Send a valid max-age cache directive
- **system**: Restore the show-all guard in system_search.tpl

### Compatibility
- **php86**: Report the strict-mode refusal once, fix docs and changelog
- **php86**: Warn on every strict-mode refusal path
- **php86**: Complete the session save-handler contract
- **php86**: Record the constructor-return fix in the changelog
- **php86**: Use bare returns in the four early-exit constructors

### Miscellaneous
- **github**: Add a pull request template with the review checklist (#175)

### Other
- Fix/273 hardening (#179)
- Adding 2.7.x versions to issue template
- Deprecate XOBJ_DTYPE_UNICODE_* datatypes (2.7.3)- #164
- Drop stray @deprecated tag from DEPRECATED_UNICODE_DATATYPES docblock
- Address review: dedupe deprecated-type list, shorten notice, suppress internal usages
- Deprecate XOBJ_DTYPE_UNICODE_* datatypes (2.7.3)

### Refactor
- **system**: Extract the tplsets path contract into PathGuard (#178)
- **search**: Normalise the row uid once, in the row normaliser
- **search**: Validate the show-all request before rendering the header

### Security
- **session**: Keep the no-resurrect gate across the validateId/read race
- **session**: Gate the timestamp upsert on a read miss

### Testing
- **quality**: Widen the constructor-return pin repository-wide (#177)
- **php86**: Cover exec() failure on the timestamp-only UPDATE branch
- **php86**: Pin the race gate and harden three tests' isolation
- **php86**: Pin the no-resurrect gate on updateTimestamp()
- **php86**: Exercise the constructor's strict-mode wiring
- **php86**: Filter for the helper's warning in the headers-sent branch
- **php86**: Assert the warnings, restore REMOTE_ADDR, cover mid-session
- **php86**: Cover create_sid, the strict-mode pin, and the timestamp upsert
- **php86**: Harden the constructor pin per review
- **php86**: Pin that the early-exit constructor yields no value
- **php86**: Drop setAccessible() ahead of its PHP 8.5 deprecation
- **php86**: Pin the parse_url shield on pre-8.6 runtimes too
- **php86**: Pin NUL-byte behavior at the parse_str and stat boundaries
- **php86**: Record the is_long()->is_int() sweep in the changelog
- **php86**: Replace deprecated is_long() with is_int()
- **search**: Read the guard contracts through named helpers
- **search**: Cover the uid write and the strict results-branch check
- **search**: Match the guard conditions loosely
- **browse**: Bind the cache-lifetime assertion to browse.php

## [v2.7.3-RC1] - 2026-08-11

### Bug Fixes
- Fix/debug-gate-on-upgraded-sites
- **db**: Let the legacy-IN diagnostic be switched on from debug.php
- **debugconfig**: Guard XOOPS_ROOT_PATH in vendor discovery
- **file**: Treat drive-letter and UNC paths as absolute
- **debug**: Keep debug-runtime.json an object when its last key is removed
- **debug**: Repair the guard chain, the constants and the reporting channel
- **debug**: Survive a missing or truncated debugconfig.php through the boot
- **system**: Guard getByDirname() on the uninstall and update confirm screens
- **textsanitizer**: Degrade invalid UTF-8 in button JS instead of throwing
- **editor**: Tighten toolbar rendering paths from second review pass
- **editor**: Harden toolbar override handling and attribute output
- **imagemanager**: Use the core form renderer and enforce authorization
- **xoopsform**: Escape element values in all renderer output contexts
- **editor**: Repair the dhtml toolbar's no-selection actions
- **php85**: Drop deprecated curl_close() calls
- **textsanitizer**: Keep code whitespace and scope the break trim to our own boxes
- **textsanitizer**: Trim the break after an unhighlighted code block too
- **textsanitizer**: Repair [code] and [quote] rendering on PHP 8.3+
- **criteria**: Render empty IN lists as a constant and convert core callers (#154)

### Features
- **debug**: Add the error-screen provider seam
- **debug**: The error screen is file-configured, and says so when it is not
- **debug**: File-based debug configuration for 2.7.3
- **editor**: Add SCEditor as an optional BBCode editor (#152)

### O