Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Offical apps | Community apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Grav CMS
  3. Grav CMS - Package Updates

Grav CMS - Package Updates

Scheduled Pinned Locked Moved Grav CMS
119 Posts 3 Posters 78.5k Views 5 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Package UpdatesP
    Package UpdatesP
    Package Updates
    wrote last edited by
    #110

    [2.1.2]

    • Update grav to 2.1.5
    • Full Changelog
    • Avatars and files uploaded to user/data are served again, and the rest of the user/.htaccess fix from 2.1.4 now reaches the folders it missed. 2.1.4 restated the site root's folder blocks without the two exceptions the root makes, so profile avatars and Flex Object image uploads came back as "forbidden" on Apache. The separate files in user/accounts, user/config and user/data also still used the directive that takes a site offline on a host with a restricted AllowOverride, so those three folders kept failing where 2.1.4 had fixed the rest. All four files now work the same way, and an upgrade replaces any of them a previous Grav wrote a file you edited yourself is left alone. Thanks @onetrev #4311
    • A premium package covered by a licence you already hold now installs, instead of being refused as unlicensed. A store can sell one licence that carries several packages a shop plugin whose payment providers come with it, say and the repository entry says so with premium.license_product. The download proxy has always honoured that, but GPM only ever looked for a key filed under the package's own name, so a customer holding one key had to paste it once per package, and bin/gpm install failed on every package they had not pasted it against. The key filed under the product a package belongs to now counts for that package, and a key filed under the package's own name still wins wherever there is one.
    • Sites on hosts with a restricted AllowOverride are no longer taken offline by the user/.htaccess file added in 2.0.19. That file used an Apache directive many shared hosts do not permit in .htaccess, and where it was not permitted Apache returned an error for everything inside user/ so the admin went blank, the theme's styles and scripts stopped loading, and the front end broke too. It kept happening after a rollback, because rolling back Grav never replaces user/. The file now does the same job with directives every host running Grav already allows. Thanks @elanorpam #4309
    1 Reply Last reply
    0
    • Package UpdatesP
      Package UpdatesP
      Package Updates
      wrote last edited by
      #111

      [2.1.3]

      • Update grav to 2.1.6
      • Full Changelog
      • A package that ships its own .htaccess can no longer opt out of the protections around user/. Those rules are pushed down into every folder beneath user/ and run first, which is what stops a plugin or theme from replacing them. A folder can still ask Apache to run them last and then stop before they are reached. That takes a deliberate line in the package's own file rather than the accidental case this guards against, but the protection Grav shipped before 2.1.4 held against it, so this restores that. A second set of rules now backs up the first using a different Apache module, one that a folder underneath cannot switch off. #4236
      • The compiled cache is written in one piece, so a busy site no longer logs Corrupt compiled cache warnings after an install or a cache clear. Every request includes the compiled copy of a YAML or markdown file without taking a lock, while the process rebuilding it truncated the file first and filled it afterwards. A request landing in between saw a syntax error, and since 2.0.20 each one wrote a warning to grav.log, which on a cold cache with the admin's parallel requests meant a burst of them for a problem that had already healed itself. The compiled file is now written next to its target and renamed over it, so a reader only ever sees a complete file. The warning stays for a file that really is broken, but no longer fires when another process is in the middle of writing it, and a corrupt file is reported once per request rather than once per read path. A compiled file that cannot be written is now a cache miss instead of a server error.
      • user/data answers correctly on a restricted host too, on sites an earlier update had put beyond the reach of 2.1.5's repair. An update in June widened that folder's file in place rather than replacing it, which produced two versions that exist only on disk in no release and in no checkout so the sweep behind 2.1.5 could not find them to list. A site carrying either one kept the directive that returns a server error for the whole folder on a host with a restricted AllowOverride, which is every image and file uploaded to user/data. Both are now recognised and replaced. #4311
      • A number field accepts every value that sits on its step, instead of refusing some of them. Checking a value against a step was done in binary floating point, where a decimal like 0.0000001 has no exact representation, so a perfectly valid entry could be rejected with no way for the person filling the form to tell why a latitude of 81.96 on a field stepping by 0.0000001 was refused. The check is now done on the digits as typed, which has an exact answer. Thanks @TheoAcker12 #3585
      • A number, range or select field no longer takes the site down when its step is any, zero, or not a number. any is the standard way to say a field has no step at all, and it was being read as zero and then divided by, which is a fatal error rather than a failed validation the same for a step left empty or set to something that is not a number. Multi-value select and checkbox fields had the same fault a few lines away. All of them now treat a step that is not a positive number as no step, which is what browsers do. Thanks @sridharkalaibala #4308
      • The last folder under user/ that could answer with a server error on a host with a restricted AllowOverride now answers correctly. 2.1.5 fixed the four files Grav ships, but a site with a user/env folder also has a file there that an earlier update wrote, and Grav has never shipped that one so it kept the directive the rest were moved off. Nothing is served from that folder, so no site was broken by it; it is a stray error page where a "forbidden" belongs. An upgrade replaces the file if it is the one Grav wrote, and leaves a file you edited alone. #4311
      1 Reply Last reply
      0
      • Package UpdatesP
        Package UpdatesP
        Package Updates
        wrote last edited by
        #112

        [2.1.4]

        • Update grav to 2.1.8
        • Full Changelog
        • Upgrading now adds the tmp/ block from 2.1.7 to an existing site's .htaccess, so upgraded Apache sites stop serving temporary files and the dashboard storage warning clears. #4316
        • Updated vendor libraries to latest versions
        • Defer OPcache compilation of newly generated YAML and Markdown cache files until they are first included, reducing cold-cache rebuild work on large sites while still invalidating stale bytecode immediately.
        • Repeated deprecation notices now share one debug trace with an occurrence count, preventing large page-tree rebuilds from filling memory and the debug toolbar with thousands of identical traces. Notices from different YAML documents and Twig source locations remain separate.
        • [security] Editor-authored Twig can no longer read the Clockwork debugger token from system configuration. Thanks @manus-pi
        • [security] Bundled nginx, Caddy, lighttpd and IIS rules now block hidden files and directories at any depth, including nested Git repositories, while still allowing .well-known for ACME challenges. Operators who copied one of these configurations must update their active server configuration. Thanks @onetrev
        • [security] Image transforms now refuse source rasters above the configured pixel limit before GD or Imagick decodes them. Thanks @manus-pi
        • Modular page content that uses request-aware Twig is now rendered for each visitor instead of being shared from the page cache. Thanks @Lxcardoza993
        • GPM now explains skipped symlinked updates and reports unwritable package directories before downloading or changing packages. Preflight annotates the same destination issues, and development builds no longer receive a misleading prompt to upgrade to an older release. #4319
        • A theme's Flex, user or config blueprints are now found, instead of being ignored unless the theme also happened to ship page blueprints. A theme supplying, say, a Flex type of its own had it quietly never register: nothing errored and nothing was logged, the type simply never appeared. Each kind of blueprint a theme ships is now registered on its own, which also keeps a theme from shadowing the blueprints Grav itself provides. Thanks @wakqasahmed #4303
        1 Reply Last reply
        0
        • Package UpdatesP
          Package UpdatesP
          Package Updates
          wrote last edited by
          #113

          [2.1.5]

          • Update grav to 2.1.9
          • Full Changelog
          • The bundled robots.txt no longer blocks pipelined CSS and JS. Disallow: /assets/ was removed, because it beat the shorter Allow: *.css$ rules and stopped Google from rendering pages on sites with the asset pipeline turned on. The CSS and JS rules now start with /, also match URLs with a query string, and explicitly allow assets under system/ and user/plugins/. Upgrades never replace robots.txt, so existing sites need to apply this change by hand.
          1 Reply Last reply
          0
          • Package UpdatesP
            Package UpdatesP
            Package Updates
            wrote last edited by
            #114

            [2.1.6]

            • Update grav to 2.1.12
            • Full Changelog
            • SVG fills that point at a gradient on the same page, such as fill: url(#linear-gradient), keep working with CSS pipelining on. Thanks @wakqasahmed #2784
            • CSS pipelining no longer breaks url() values that aren't file paths, such as about:blank or blob: links, and now correctly rewrites paths written as URL(...) or with spaces inside the brackets.
            • Files under .well-known/ are now served when running Grav with the built-in PHP server (bin/grav server), matching the shipped web server configs. Thanks @wakqasahmed #4016
            • Themes whose stylesheets use @import, such as Learn2, look right again with CSS pipelining and minification on. 2.1.10 could move a block of the theme's styles to the top of the combined file along with the import. Thanks @Gazoo #4330
            • The shipped web server configs now block running PHP and other scripts in images/ and assets/, and upgrading adds the same rule to an existing site's .htaccess.
            • Uploaded filenames are now rejected when any extension in the name is a dangerous one, not just the last, so evil.php.jpg can't run as PHP on servers that map PHP with AddHandler.
            • Multipart PATCH requests are now parsed, instead of being skipped because of a typo in the method check.
            • A stylesheet the CSS minifier can't handle no longer breaks the page. Its group is served unminified instead, in the original order, and cached like any other bundle. Thanks @wakqasahmed and @sridharkalaibala #4305
            • Space-separated rgb() and hsl() colours are no longer mangled or dropped when CSS minification is on. Thanks @onetrev #4305
            • Watermarks now land in the right place on resized, cropped and derivative images, including retina files, instead of being placed for the original size or missed entirely. Thanks @phmg701 #4322
            1 Reply Last reply
            0
            • Package UpdatesP
              Package UpdatesP
              Package Updates
              wrote last edited by
              #115

              [2.2.0]

              • Update grav to 2.2.0
              • Full Changelog
              • Rebuilding the pages cache no longer writes a compiled file for every page, so the first request after a cache clear is much faster on large sites.
              • A new pages.frontmatter.native_yaml setting reads page frontmatter with the much faster YAML extension when the server has it installed. It is off by default because the extension reads unquoted dates and yes/no differently.
              • pages.lazy_index now defaults to auto, which uses the page index on sites with 1,000 pages or more and the classic pages cache on smaller ones, so large sites load pages faster and use far less memory without any setup.
              • CSS minification now uses wikimedia/minify, which understands modern CSS and is about 15 to 25 times faster on real stylesheets.
              • Sites on Apache older than 2.4.8, common on Plesk and CentOS 7 hosts, no longer answer 500 for everything under user/ after upgrading, and upgrading fixes the .htaccess files earlier releases wrote there (grav-plugin-admin2#179)
              • Plugins' onShutdown work runs again after Admin Next saves on sites with session.read_and_close on, when another plugin had already finished the response.
              • Deleting or renaming a page folder is now picked up without clearing the cache.
              • The file change check no longer counts files that only contain .md somewhere in their name, such as page.md.bak, or whose name merely ends in yaml.
              • Searching Flex pages now matches a page's route as well as its title, slug and menu.
              • calc() inside @media, @supports and @container conditions keeps its spacing when CSS is minified, so browsers no longer drop those blocks.
              1 Reply Last reply
              0
              • Package UpdatesP
                Package UpdatesP
                Package Updates
                wrote last edited by
                #116

                [2.2.1]

                • Update grav to 2.2.1
                • Full Changelog
                • The .htaccess files under user/ no longer use mod_rewrite, so hosts that broke on them, such as some shared Apache setups, serve the admin, theme files and images again. Upgrading replaces the copies Grav wrote and leaves edited ones alone (#4309)
                1 Reply Last reply
                0
                • Package UpdatesP
                  Package UpdatesP
                  Package Updates
                  wrote last edited by
                  #117

                  [2.2.2]

                  • Update grav to 2.2.2
                  • Full Changelog
                  • The .htaccess and Caddy configs now let browsers keep the Admin panel's bundled files for a year, since their names change whenever they do. On Apache, copy the new block from webserver-configs/htaccess.txt into an existing site's .htaccess to get it (getgrav/grav-plugin-admin2#181)
                  • Upgrading Grav from the admin on Windows, for example under Laragon, no longer deletes index.php and leaves the site showing a 404 page (forum)
                  • An upgrade no longer blocks most of the Twig sandbox, such as date, max and batch, on sites whose security.twig_sandbox lists only add entries. Sites an earlier upgrade already did this to get those defaults back.
                  • A fresh install now records the current upgrade level, so its first upgrade no longer reruns fixes meant for older installs.
                  • [security] Updated the bundled DOM sanitizer to 1.0.18, which closes several ways a crafted stylesheet could hide an external resource reference using CSS escapes, such as a backslash-newline line continuation (GHSA-94fv-h7hv-365q).
                  • Commands run by the scheduler, such as a plugin's bin/plugin worker, now run in the same environment as the scheduler, so a site started with bin/grav scheduler --env <host> no longer runs its jobs without the settings in user/env/<host>/config.
                  • With pages.media_route_urls enabled, page files whose names contain a space or an accented character, such as foo bar.pdf or br.png, no longer return a 404 (#4332)
                  • An image used more than once in Markdown no longer picks up the query parameters, #fragment or style of the earlier uses, and keeps its retina srcset after an earlier use was cropped or resized. Thanks @wakqasahmed (#3567, #4333)
                  • The content XSS check now also flags a javascript: link with a space after the colon, and no longer misses a link when the text elsewhere contains an encoded character it could not decode. Thanks @manus-pi
                  • [security] With image URL actions turned on, the image pixel limit now measures the image each resize actually produces, including one-dimension, percentage and zoomCrop resizes. Thanks @manus-pi
                  1 Reply Last reply
                  0
                  • Package UpdatesP
                    Package UpdatesP
                    Package Updates
                    wrote last edited by
                    #118

                    [2.2.3]

                    • Update grav to 2.2.3
                    • Full Changelog
                    • Updated Twig to 3.30 (through Grav's getgrav/Twig fork), which brings upstream's fixes since 3.29, among them faster object attribute reads and macros declared by a parent template, a for loop variable that was undefined inside a nested loop's sequence, and the spread operator now rejected outside sequences, mappings and call arguments.
                    • Theme and plugin templates now compile without any of the Twig sandbox's checks, which only ever apply to Twig in page content, so pages render faster (about half the Twig time on a busy listing template, within a few percent of running with no sandbox at all). Twig in page content, and any template rendered with the sandbox switched on, is checked exactly as before. That includes a theme template that was already loaded when a {% sandbox %} block or a sandboxed include reaches it, along with its blocks, macros and parent: it renders from a separately compiled copy with every check in place, so it gives the same output, and blocks the same things, as before. This uses a new opt-in feature of Grav's Twig fork (getgrav/Twig), so it needs that fork's matching commit.
                    • Grav's Twig now refuses a template loaded by a different Twig environment when one is passed to include() or {% include %}, the same as Twig itself does, instead of rendering it with the other environment's settings. A template object from Grav's own environment passed on its own now renders instead of failing with a type error.
                    1 Reply Last reply
                    0
                    • Package UpdatesP
                      Package UpdatesP
                      Package Updates
                      wrote last edited by
                      #119

                      [2.2.4]

                      • Update grav to 2.2.4
                      • Full Changelog
                      • A page's Markdown version (<route>.md) and llms-full.txt include the full page again on sites running the Archives plugin, instead of only a title and navigation links #4339
                      • An uploaded SVG whose doctype declares entities is no longer emptied by the sanitizer (rhukster/dom-sanitizer 1.0.19)
                      • A multisite that keeps each site in user/env/<host>/ loads its theme, plugin and media files again. The bundled server configs protect config/, accounts/ and data/ inside each env folder the same way they protect them in user/, and the upgrade updates an existing .htaccess, and the user/env/.htaccess an earlier upgrade added, to match. Sites on nginx, Caddy, lighttpd or IIS need to copy the new rules from webserver-configs/ by hand #4335
                      • Saving a page whose blueprint has a list containing only an elements field no longer fails with an error, and the fields inside each element now belong to their list item instead of the top of the blueprint, where they could clash with a field of the same name (rockettheme/toolbox 2.0.1) #4337
                      1 Reply Last reply
                      0

                      Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                      Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                      With your input, this post could be even better 💗

                      Register Login
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search