Grav CMS - Package Updates
-
[1.10.14]
- Update grav to 2.0.14
- Full Changelog
- Removed old JQuery
2.1.4. However2.2.4and3.7.1remain for legacy support - [security] An administrator with account-management rights can no longer grant themselves super-admin access by saving it into a user group's permissions, a protection the account form already had (GHSA-xhfv-7758-r9hx).
- [security] The content security scan no longer reports a page as clean when it was unable to examine it, closing two ways a page editor could hide a script from it: a single invalid character anywhere in the content, and padding a tag out to several thousand characters (GHSA-q2j8-x8hf-63ch).
-
[1.10.15]
- Update grav to 2.0.15
- Full Changelog
- A plugin's blueprints can use the data providers that plugin ships again, instead of having every one of them refused by a check that only recognised the providers core itself registers (getgrav/grav-plugin-email#193). Fields defined in page frontmatter are held to the stricter rule instead, which is where the risk actually was.
- [security] A configuration admin can no longer reach an unvetted built-in routine by writing a blueprint field's data provider as a plain function name, a spelling that was still being checked against a list of known-bad names rather than the list of approved ones (GHSA-f8wv-xp27-6gq7).
- [security] The content security scan now reads an unpaired quote inside an unquoted attribute value the way a browser does, closing another way a page editor could hide a script from it (GHSA-vfmf-q6x9-cw96).
- [security] The media URL in an audio or video tag is now escaped, so a filename carrying markup can no longer add its own attributes to the player (GHSA-6qw9-4vv5-jr97).
- JSON responses no longer fail outright when the data contains invalid UTF-8.
json_encode()returnsfalseon malformed bytes, and the PSR-7 response body is type-hintedstring|resource|StreamInterface, so thatfalsecame back out as an unhandledTypeErrorfrom inside the vendor stream rather than as a response. AffectedcreateJsonResponse()and both JSON error responses inControllerResponseTrait, where an exception message carrying a bad byte would take out the error handler itself, plus the Clockwork data endpoint inDebugger. Bad bytes are now substituted, and the remaining structural failures (recursion depth,INF/NAN) raise a catchableJsonExceptioninstead of a silentfalse. Output for valid data is unchanged. - [security] The fast static asset server now keeps a request inside the directory the site published, instead of also allowing any neighbouring directory whose name starts with the same letters (GHSA-4v9q-p283-qc2m).
- [security] File uploads now reject a few more extensions that browsers run script from, or that a server may hand to PHP:
xhtml,xht,svgz,php7,php8,pht,phtmandphps(GHSA-66xf-ggf4-6hmc). - [security] The bundled
Caddyfileprotections did nothing. They were written as nginx-style regexes, which Caddy reads as literal paths that never match, and therespondthey redirected to ran after the catch-all rewrite had already claimed the request. A site served with this config handed outuser/accounts/,user/config/,logs/,composer.lock, page files, and thesystem/andvendor/folders to anyone who asked. The rules are now namedpath_regexpmatchers answering403directly, inside arouteblock so they run before the rewrite, and they were checked request by request against the.htaccessbehaviour.
-
[1.10.16]
- Update grav to 2.0.17
- Full Changelog
- Updated vendor libs to latest versions
- The list of groups on the account form is now read through the current user groups system, retiring a routine deprecated since Grav 1.7.
- [security] Updated the bundled DOM sanitizer to 1.0.13, which stops CSS comments from hiding dangerous values and covers image loading through
image-set(), so untrusted SVG or HTML can no longer reference external resources those ways (GHSA-ww22-4mqv-x5w3). - [security] The site, system and theme settings offered to Twig written inside page content are now filtered by the same denied-paths list that already covered
config, so a page editor can no longer read secrets such as a Redis password straight out of them (GHSA-p597-crqc-m349). - [security] Twig written into a form's email settings now runs under the same restrictions as Twig written into page content, closing a route that let someone with only page-editing rights run commands on the server (GHSA-gh8j-q67c-j53f).
- [security] Form security tokens are now compared with a routine that takes the same amount of time whichever characters differ, so the check can no longer hint at how much of a guess was right (GHSA-38p6-h87p-r4cg).
- [security] The check for whether a visitor arrived from your own site now requires a full address match, so another site whose domain merely begins with yours no longer counts as your own (GHSA-9ccq-2jfg-qw33).
- [security] Scheduler job locks are now kept inside your site rather than in the shared system temp folder, so another account on the same server can no longer redirect a lock write to a file of its choosing (GHSA-q8w8-6cq5-j4h2).
- [security] Deleting, renaming and copying a media file now check the whole path rather than just the file's own name, so a plugin calling those routines directly cannot reach a file outside the media folder (GHSA-jq29-c7v8-rg55).
- [security] The
media_directory()Twig function now only accepts folders inside your site, so Twig written into page content can no longer list files or republish images from elsewhere on the server (GHSA-47ch-6w46-6xm7).
-
[1.10.17]
- Update grav to 2.0.18
- Full Changelog
- [security] Updated the bundled DOM sanitizer to 1.0.14, which closes two further ways a crafted stylesheet could hide an external image reference from the checks added in the previous release (GHSA-ww22-4mqv-x5w3).
- [security] Modular pages are now checked for cross-site scripting when they are saved, closing a way for a page editor to store a script that ran for every visitor (GHSA-fg8g-663r-f366).
- [security] The Twig
sortandfindfilters no longer run a plain function name as a callable inside the content sandbox, closing a way for a page editor to execute arbitrary PHP (GHSA-p6qj-p5m7-f62h). - A blueprint that builds on another one can again fill dropdowns from its own PHP, which mostly affected themes because their page blueprints nearly always extend the default one (getgrav/grav-plugin-email#193).
- The Scheduler no longer fails outright on hosts that disable PHP's
proc_open, so scheduled jobs can still be viewed and edited there getgrav/grav-admin-next#16 - A scheduled job that cannot be started on such a host is now reported as failed with an explanation, instead of stopping the whole scheduler run
- Grav now works out who the site runs as without starting a shell, so that detail still appears when external commands are unavailable
- The record of when the scheduler last ran is now written to a fixed location rather than one relative to wherever the trigger happened to run from
- Grav now decides whether the scheduler is being triggered by checking that each job has run when its own schedule says it should have, instead of requiring a run in the last two minutes, so a sparse crontab, a webhook or a scheduled task on Windows all count
-
[1.10.18]
- Update grav to 2.0.19
- Full Changelog
- You can now tighten the Twig content sandbox below its built-in defaults with new
denied_*settings insecurity.yaml. - The "Twig in Content" report can show the effective sandbox policy, so you can see exactly what page content is allowed to do.
- A theme or plugin that ships its own
.htaccesscan no longer switch off the protection on its own folder, which used to leave its configuration and template files downloadable #4236 - Twig in page content now renders on new installs by default, instead of appearing as raw text until the setting was turned on.
- The long Twig sandbox allowlists now ship built into Grav, so
security.yamlonly records your own additions and future security updates to the defaults reach every site. - Existing sites that had trimmed those allowlists to tighten them keep exactly that policy after upgrading, now recorded as explicit
denied_*entries. - Removed two rarely-used Twig sandbox switches (
loggingandadmin_hint); both behaviours are now always on. - The content cross-site scripting check no longer objects to harmless
<option>and<select>markup, whose original issue is fixed in the form field that actually rendered it. - Sites running with the Twig 2 compatibility setting no longer crash with a server error on every page once an update clears the template cache #4235
-
[1.10.19]
- Update grav to 2.0.20
- Full Changelog
- Updated the bundled Twig fork to the current 3.x, picking up the correctness and sandbox improvements from the 3.27 and 3.28 releases.
- Grav now runs on Twig 3.28 and newer, which tightened the escaping method that Grav's compatibility shim replaces and would otherwise stop the site with a server error.
- [security] Page content can no longer register a script or stylesheet through the Twig content sandbox, and asset URLs are now escaped where the tag is built, closing a way to inject markup into a rendered page.
- [security] The
read_filecapability no longer includes the user data folder by default, so page content can no longer be used to publish form submissions and other stored data. - [security] A proxy address that carries a username and password is now hidden from sandboxed page content, matching the other credentials already redacted there.
- [security] Custom Twig sandbox denial rules now take effect regardless of how the class name is capitalised, and can no longer be silently bypassed through a parent class or interface.
- A damaged page cache file is now rebuilt from the original page instead of stopping the site with a server error #4239
- Images and links in page content now work when the file name contains a colon, such as a screenshot named after a timestamp #3933
- A page that sets a full web address as its canonical route now uses that address on its own, instead of joining it onto the site's own address and breaking sitemaps and canonical links #4023
- Turning on asset timestamps now gives each stylesheet and script its own marker taken from when that file last changed, so editing one file no longer waits on an unrelated change before visitors see it #4049
-
[1.10.20]
- Update grav to 2.0.21
- Full Changelog
- Form fields no longer print their HTML attributes as text above the field, a problem the Twig update in 2.0.20 introduced on every form #4256
- A custom text escaper registered by a plugin now works again, instead of stopping the page with an error the first time a template used it
-
[2.0.0]
- Switch to admin2 plugin
-
[2.0.1]
- Update grav to 2.0.24
- Full Changelog
- A dependency can now name the generation of Grav it is for. A plugin that supports both 1.7 and 2.0 often needs a different version of the same dependency on each, so a
dependenciesentry takes an optionalgravkey:- { name: form, version: '>=9.1.0', grav: '2.0' }. Entries without it apply everywhere, so existing blueprints are unchanged. See Plugin Compatibility - A new
system.images.progressive_jpegsetting, on by default, controls whether resized and cached JPEGs are saved as progressive - An image default such as
resizeset insystem.images.defaultsworks again. Every image manipulation was being skipped since 2.0.22, leaving only the loading and decoding hints #4282 - Resized and cached JPEGs are saved as progressive again, so a photo appears as a whole blurry image that sharpens instead of filling in one line at a time. It has been Grav's default since 2014 but silently stopped working in 1.4.6 #4284
-
[2.0.2]
- Update grav to 2.0.26
- Full Changelog
- Plain text that happens to contain a word ending in
data,feedor another URI scheme name no longer blocks a page from saving with "Potential XSS issues detected". The check matched the scheme anywhere inside a word, so a Hungarian sentence ending in "mondata:" or an English one mentioning "metadata:" was read as adata:URI. Thanks to @csbrny #619 - A new
pages.media_route_urlssetting insystem.yaml, off by default, links a page's media by its page route instead of its path on disk, so plugins can apply the page'saccessrules to media requests. Resized images keep serving from the image cache - Every web server config now carries a commented rule for denying direct access to
user/pages, which only becomes safe to enable oncepages.media_route_urlsis on - Now depends on a released
rockettheme/toolbox2.0 rather than tracking its development branch, so a build always resolves to the same code - An operator who manages users can no longer give themselves full admin rights. Permission fields that only a super admin may write were guarded by name, and writing the same field under its flattened name slipped past that guard. Thanks to @movon-ava
- Twig in page content can no longer read the site's configuration through the
arrayfilter. The|arraycast was the one conversion that never asked the sandbox whether it was allowed, so it could turn Grav's internal service registry into a plain list and read the settings the sandbox exists to keep out of page content, including plugin passwords and API keys. Thanks to @1diot9 and @AlpetGexha - A page can no longer capture the session of an administrator who views it. Page content could read the visitor's cookies, and the finished page was stored in a cache shared by everyone, so an administrator's session could be handed to the next visitor. Cookie reading is no longer available to page content, and pages that run editor-written code are no longer cached after that code runs. Thanks to @canhieu
- The bundled IIS and lighttpd configs now block sensitive files whatever the capitalisation of the request. Only the Apache and PHP rules were corrected when this was last fixed. Anyone serving Grav with the bundled
web.configorlighttpd.confshould re-copy the sample, as the updater only heals.htaccess. Thanks to @movon-ava onShutdownnow fires after a request that ended throughclose()orredirect(), not only after a rendered page. Those requests echoed their response and exited before the shutdown handler was registered, so a plugin doing slow work after the response (sending queued mail, warming a cache) never ran on a form submit that redirected. The non-FastCGI fallback also stops trying to set headers once they have been sent- A page dated with an unquoted
date: 2022-01-06header no longer lands in the year 7200. The YAML parser reads an unquoted date as a date and hands over a timestamp rather than a string, which the date parsing then misread. Thanks to @wakqasahmed #3812
-
[2.0.3]
- Update grav to 2.0.27
- Full Changelog
- Grav 2.0 sites can update to 2.1.
bin/gpm selfupgradetreated each minor release as a separate line, the way 1.7 and 1.8 were, so a 2.0 site was told it was up to date while 2.1.0 was out. Only a new major version now needs a manual move #4299 - When a new major version of Grav is out,
bin/gpm selfupgradesays so and links to the migration guide instead of only reporting that the site is up to date - Licence keys from other stores are accepted. The key format check only knew the Grav Premium format, so a KahunaCart key such as
KC-XXXX-XXXX-XXXX-XXXXwas refused by the API plugin's install endpoint and by License Manager. The check now only turns away what no store could have issued - When getgrav.org refuses a premium download for a reason the person can act on, such as an updates window that has ended,
bin/gpm installprints the store's explanation instead of only "Unauthorized Premium License Key". The API plugin bundled with this release relies on it
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login