This release contains security fixes for the 3.x line. Upgrading is recommended for every 3.x install. Details will be published in security advisories.
Changed
- The picker only works with media its field allows.
- The picker and its media panel only list, search, insert and act on media on the field's disk, of its accepted types, and for the current tenant.
- Wildcards never match scriptable types.
- New selections outside those settings fail validation.
- Media already saved on a record keeps loading while it exists and belongs to the tenant. That includes pickers in Repeaters and Builders, except inside conditionally visible components.
- Saving a curation needs the media's
updateability when a Media policy is registered.- The media can't be changed from the browser.
- The crop box is kept within the image.
- Output is capped by the new
curator.curation_max_dimension(default 4096). - The source image is now read from the media's disk instead of over HTTP.
What's Changed
- fix: authorize curation saves and bound the curation's size by @awcodes in #769
- fix: scope the picker's media to the field's settings by @awcodes in #770
Full Changelog: v3.7.12...v3.7.13