I'm wondering about the practical outer limits of what drupal can handle. I have a client who currently has a site with about 40k regular users, and wants to blog-enable them. I'm reasonably confident that I can handle the user detail sync stuff, and have a few ideas about mysql changes that might be needed, but I'm wondering what I've not thought about.
Is anyone out there running a site of that sort of scale with drupal? If so, got any words of wisdom to share?
I have a fresh 4.1.0 install (openbsd/mysql/apache 1.3.26). Whenever I add themes to the themes directory (as per the instructions on this site), they show up in the "site-admin > themes" page, and I can check them on or off. The only problem is that they show up as a DUPLICATE name of another theme already there. I just installed jeroen, and now it lists two identical themes called Goofy. Checking either 'Goofy' theme results in only blank pages being generated until I go delete the offending theme.
I am sure I saw a note about this somewhere on this site before I installed, at the time I did not think of it as I was sure it would not happen to me. But now I have realized I do have that problem.
After reading an article about security and various content management apps including Dupal, I'm curious if others could comment about Drupal's security?
Well, "IMG SRC="javascript:alert('insecure')" did not seem to have any effect.