github awcodes/filament-curator v3.7.12

latest releases: v3.7.13, v5.5.3, v4.2.3...
6 hours ago

This release contains security fixes for the 3.x line. Upgrading is recommended for every 3.x install. Details will be published in security advisories.

After upgrading

Check existing media for files stored under an unsafe extension, then repair them:

php artisan curator:repair-extensions --dry-run   # report only
php artisan curator:repair-extensions
  • What it renames: files whose stored extension is unsafe. HTML, XML or JavaScript content is renamed to .txt.
  • Keep the output: it prints each rename as old -> new.
  • Links: a renamed file's URL changes, so update any copies of the old link.
  • Left alone: case-only differences, such as .JPG. Nothing is deleted.

Changed

  • The media panel's settings come from the server.
    • The picker and the TipTap media action pass the panel's settings as an encrypted payload that expires after ten minutes. The panel ignores anything else.
    • The panel's configuration properties are locked.
    • Selected media is reloaded by id before it's inserted.
    • If your app dispatches open-modal to curator-panel with a plain settings array, use CuratorPanel::encryptSettings() instead.
  • Upload types are detected from the file's contents.
    • Each upload is stored under the extension of its detected type.
    • HTML, XML and JavaScript types are accepted only when listed exactly, never through a wildcard such as text/*.
    • SVGs are sanitized before they're written to disk. An SVG that can't be sanitized is rejected.
  • The picker's download action uses the media record's own file.
    • It applies the panel's tenant scoping and view policy check.
    • The README's example policy now includes view. If your policy doesn't define it, downloads are denied.

Fixed

  • Glide prefix: media stored under a folder named like the Glide route prefix (curator/ by default) is now served correctly.
  • JavaScript values: values rendered into JavaScript in the views are now encoded consistently.
  • Upload fields: only genuine uploads are saved.

Added in #759, #760 and #761. CI was fixed in #762.

What's Changed

  • ci: allow PHPUnit 10.5.36 for the PHP 8.1 job by @awcodes in #762
  • fix: resolve the picker's download from the media record by @awcodes in #759
  • fix: store uploads under the extension of their detected type by @awcodes in #760
  • fix: keep the media panel's settings on the server by @awcodes in #761

Full Changelog: v3.7.11...v3.7.12

Don't miss a new filament-curator release

NewReleases is sending notifications on new releases.