github awcodes/filament-curator v4.2.2

latest releases: v3.7.13, v5.5.3, v4.2.3...
6 hours ago

This release contains security fixes for the 4.x line. Upgrading is recommended for every 4.x install. Details will be published in security advisories.

5.x also supports Filament 4, so you can move to Curator 5.x without changing Filament.

After upgrading

Check existing media for files stored under an unsafe extension, then repair them:

php artisan curator:repair-extensions --dry-run   # report only
php artisan curator:repair-extensions
  • What it renames: files whose stored extension is unsafe. HTML, XML or JavaScript content is renamed to .txt.
  • Keep the output: it prints each rename as old -> new.
  • Links: a renamed file's URL changes, so update any copies of the old link.
  • Left alone: case-only differences, such as .JPG. Nothing is deleted.

Changed

  • The media panel's settings are fixed when it opens.
    • Its configuration properties are locked, so changing one from the browser now throws CannotUpdateLockedPropertyException.
    • Folder navigation only goes to the disk root, the configured directory, or folders that hold media.
    • Inserted media is reloaded by id.
  • Upload types are detected from the file's contents.
    • Each upload is stored under the extension of its detected type.
    • HTML, XML and JavaScript types, and application/octet-stream, are accepted only when listed exactly, never through a wildcard such as text/*.
    • SVGs are sanitized before they're written to disk. An SVG that can't be sanitized is rejected.
  • The picker's download action uses the media record's own file. It requires the Media policy's view ability.
  • Glide no longer sets base_url. Existing image URLs are unchanged.

Fixed

  • Tenancy: uploads record the current tenant when tenancy is enabled. Tenancy enabled only in config no longer produces a tenant key named _id.
  • Glide prefix: media stored under a folder named like the Glide route prefix (curator/ by default) is now served correctly.
  • JavaScript values: values rendered into JavaScript in the views are now encoded consistently.
  • Upload fields: only genuine uploads are saved.
  • Old Office and plain-text files: legacy Office files (.doc, .xls, .ppt) keep their type. .csv and .ics files detected as plain text get their own type.
  • PHP 8.2 and 8.3: uploads no longer call mb_ltrim, which isn't available on PHP 8.2 or 8.3 without a polyfill.
  • Removed: the unused CuratorPanel::setMediaForm() method.

Added in #756, #757 and #758.

What's Changed

  • fix: resolve the picker's download from the media record by @awcodes in #756
  • fix: store uploads under the extension of their detected type by @awcodes in #757
  • fix: keep the media panel's settings on the server by @awcodes in #758

Full Changelog: v4.2.1...v4.2.2

Don't miss a new filament-curator release

NewReleases is sending notifications on new releases.