NodeBB - Package Updates
-
[2.31.4]
- Update NodeBB to 4.14.4
- Full Changelog
- trust_proxy upgrade script writes to wrong config.json when started with --config (breaks Docker logins) (#14527) (
29f90de)
-
[2.31.5]
- Update NodeBB to 4.14.5
- Full Changelog
- clear session info when switching users in doLogin (
bc206f6) - replace outdated .includes() check for AP header in webfinger query method, in favour of Helpers.assertAccept (
2079ea0) - guard title regeneration in inbox.update behind posts.isMain (
94feb90) - only allow self/admins/gmods to view/list emails (
a018478) - enforce same checks on topic room enter as controller (
54ff68b) - search by email array bypass (
5029739) - dont return category if user doesnt have find privilege in getSelectedCategory (
5a9d7f7) - rss feed privilege check for topic feeds (
2cc3ae1) - private upload path bypass (
35e7587) - closes #14528, encode uid in group calls (
c857090)
-
-
[2.31.7]
- Update NodeBB to 4.14.7
- Full Changelog
- add a middleware to require reauth on api routes (
69e749a) - use renderCategory for move event (
6972b70) - closes #14550, closes #14549 (
5f6ddbd) - closes #14548, wait for parsing of input elements before selecting (
0d67edd) - hide URL profile upload when uploads are disabled (#14547) (
fafced7) - use isSafeHref on user.url and category.url (
26333b8) - privileges: route ActivityPub URIs to fediverse pseudo-user check (
ab95445) - activitypub: enforce attributedTo origin check in inbox handlers (
f93507a)
-
[2.31.8]
- Update NodeBB to 4.14.8
- Full Changelog
- typo on reauthAt (
f29db71) - don't save req into post queue (
28899f7) - closes #14553, closes #14554 (
37c1853) - sanitize system messages (
f5be7f6) - handle both local and remote users' aboutme identically (
3f18849) - validate group hex colors (
a30dfd1) - add priv check to loading profile pictures (
707bfe0) - reject invalid cid in topic post route (
35c4975) - xss in room rename event in chat modals (
55b1ea5) - api: exclude cookie header from buildReqObject to prevent session token exposure in post queue (
e44d909)
-
[2.31.9]
- Update NodeBB to 4.14.9
- Full Changelog
- changing others emails requires password reauth, closes #14575 (
4ea6f9e) - don't display tokens on /admin/api page (
b7e5d85) - require password for creating master token (
7b7b7d2) - selector in chats & modals (
56c6115) - closes #14591, remove tokens if email removed (
349797a) - closes #14590 (
ce2f54e) - bring back logout message pretranslate (
3f7e6bf) - redirect to account handling only /login (
9d0c76e) - password confirm modals for admin add/remove (
9b72ca3) - closes #14569, prevent socket.emit('admin.xxx') if (
0d07382)
-
The update 2.31.9/4.14.9 has been revoked due to an upstream regression blocking all new user registration.
See: https://community.nodebb.org/topic/19422/bug-registration-fails-with-csrf-forbidden-error-on-post-register-complete-after-updating-to-v4.14.9 -
[2.31.10]
- Update NodeBB to 4.14.10
- Full Changelog
- closes #14580, dont send 'off' to digest.execute (
5ad30d4)
-
[2.32.0]
- Update NodeBB to 4.15.0
- Full Changelog
- feat: allow chat and chat:privileged privileges for fediverse group (#915b6ac)
- feat: update uploads to look nicer (#5cdf3aa)
- feat: pass opts to filter:user.create and action:user.create (#95e7da9)
- feat: add toggle to disable IP address logging (#db662ff)
- fix: don't expose user existence if visitor can't view users (#12447) (#61a7a0a)
- fix: reject SSO auth via callback handler, if state parameter isn't passed in by client (unless checkState is false) (#6ba24ed)
- fix: remove rss_token from exported user profile data (#6776cc4)
- fix: upgrade privilege check in api.users.addEmail to check admin:users instead of just privileges.users.canEdit (#35deb33)
- fix: require admin:admins-mods to modify administrators group membership (#9ddaec7)
- fix: add response size limit to prevent memory exhaustion (#0f2cc70)
-
[2.32.1]
- Update NodeBB to 4.15.1
- Full Changelog
- privileges: add "All Categories" aggregate view to admin privileges page (#14303) (
7156e73) - allow delegating user management ACP pages via admin:users (#14629) (
6cc33c3) - allow granting post edit permission to groups (#14625) (
f5f9439) - closes #14635, fix reporterUid (
e3ac49b) - honor topic sort in navigator scroller, closes #12480 (#14634) (
47bb314) - send unread count with new notifications (#14632) (
56ade8c) - resync notification count when loading the notification list (#14631) (
f01b041) - mark chat notifications read when received in the open room (#14627) (
daa65da) - autocomplete menu position in rtl (#14626) (
9cfc724) - enforce email:disableEdit in the email change interstitial (#14620) (
d7e6f92)
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login