This release contains security fixes for the 3.x line. Upgrading is recommended for every 3.x install. Details will be published in security advisories.
After upgrading
Check existing media for files stored under an unsafe extension, then repair them:
php artisan curator:repair-extensions --dry-run # report only
php artisan curator:repair-extensions- What it renames: files whose stored extension is unsafe. HTML, XML or JavaScript content is renamed to
.txt. - Keep the output: it prints each rename as
old -> new. - Links: a renamed file's URL changes, so update any copies of the old link.
- Left alone: case-only differences, such as
.JPG. Nothing is deleted.
Changed
- The media panel's settings come from the server.
- The picker and the TipTap media action pass the panel's settings as an encrypted payload that expires after ten minutes. The panel ignores anything else.
- The panel's configuration properties are locked.
- Selected media is reloaded by id before it's inserted.
- If your app dispatches
open-modaltocurator-panelwith a plain settings array, useCuratorPanel::encryptSettings()instead.
- Upload types are detected from the file's contents.
- Each upload is stored under the extension of its detected type.
- HTML, XML and JavaScript types are accepted only when listed exactly, never through a wildcard such as
text/*. - SVGs are sanitized before they're written to disk. An SVG that can't be sanitized is rejected.
- The picker's download action uses the media record's own file.
- It applies the panel's tenant scoping and
viewpolicy check. - The README's example policy now includes
view. If your policy doesn't define it, downloads are denied.
- It applies the panel's tenant scoping and
Fixed
- Glide prefix: media stored under a folder named like the Glide route prefix (
curator/by default) is now served correctly. - JavaScript values: values rendered into JavaScript in the views are now encoded consistently.
- Upload fields: only genuine uploads are saved.
Added in #759, #760 and #761. CI was fixed in #762.
What's Changed
- ci: allow PHPUnit 10.5.36 for the PHP 8.1 job by @awcodes in #762
- fix: resolve the picker's download from the media record by @awcodes in #759
- fix: store uploads under the extension of their detected type by @awcodes in #760
- fix: keep the media panel's settings on the server by @awcodes in #761
Full Changelog: v3.7.11...v3.7.12