This release contains security fixes for the 4.x line. Upgrading is recommended for every 4.x install. Details will be published in security advisories.
5.x also supports Filament 4, so you can move to Curator 5.x without changing Filament.
After upgrading
Check existing media for files stored under an unsafe extension, then repair them:
php artisan curator:repair-extensions --dry-run # report only
php artisan curator:repair-extensions- What it renames: files whose stored extension is unsafe. HTML, XML or JavaScript content is renamed to
.txt. - Keep the output: it prints each rename as
old -> new. - Links: a renamed file's URL changes, so update any copies of the old link.
- Left alone: case-only differences, such as
.JPG. Nothing is deleted.
Changed
- The media panel's settings are fixed when it opens.
- Its configuration properties are locked, so changing one from the browser now throws
CannotUpdateLockedPropertyException. - Folder navigation only goes to the disk root, the configured directory, or folders that hold media.
- Inserted media is reloaded by id.
- Its configuration properties are locked, so changing one from the browser now throws
- Upload types are detected from the file's contents.
- Each upload is stored under the extension of its detected type.
- HTML, XML and JavaScript types, and
application/octet-stream, are accepted only when listed exactly, never through a wildcard such astext/*. - SVGs are sanitized before they're written to disk. An SVG that can't be sanitized is rejected.
- The picker's download action uses the media record's own file. It requires the Media policy's
viewability. - Glide no longer sets
base_url. Existing image URLs are unchanged.
Fixed
- Tenancy: uploads record the current tenant when tenancy is enabled. Tenancy enabled only in config no longer produces a tenant key named
_id. - Glide prefix: media stored under a folder named like the Glide route prefix (
curator/by default) is now served correctly. - JavaScript values: values rendered into JavaScript in the views are now encoded consistently.
- Upload fields: only genuine uploads are saved.
- Old Office and plain-text files: legacy Office files (
.doc,.xls,.ppt) keep their type..csvand.icsfiles detected as plain text get their own type. - PHP 8.2 and 8.3: uploads no longer call
mb_ltrim, which isn't available on PHP 8.2 or 8.3 without a polyfill. - Removed: the unused
CuratorPanel::setMediaForm()method.
What's Changed
- fix: resolve the picker's download from the media record by @awcodes in #756
- fix: store uploads under the extension of their detected type by @awcodes in #757
- fix: keep the media panel's settings on the server by @awcodes in #758
Full Changelog: v4.2.1...v4.2.2