This release contains security fixes for the 4.x line. Upgrading is recommended for every 4.x install. Details will be published in security advisories.
After upgrading
Purge Glide's cache (storage/app/.cache by default) and any CDN in front of your media.
Changed
- Private media gets expiring Glide URLs.
- Size URLs (
thumbnail_url,medium_url,large_url) and the Glider for media that isn't public carry a signed expiry. They're served with private cache headers. - The expiry is set by the new
curator.temporary_url_expirationconfig (minutes, default 5). - Originals Glide can't resize, such as PDFs and video, are no longer streamed through permanent URLs.
- Public media URLs and caching are unchanged.
- Glide URLs already stored for private media stop working.
- Size URLs (
- The picker only works with media its field allows.
- The picker and its media panel only list, search, insert and act on media on the field's disk, of its accepted types, inside
limitToDirectory(), and for the current tenant. - Wildcards never match scriptable types.
- New selections outside those settings fail validation.
- Media already saved on a record keeps loading.
- The rich editor's media modal uses Curator's disk unless the editor sets its own.
- The picker and its media panel only list, search, insert and act on media on the field's disk, of its accepted types, inside
- Saving a curation needs the media's
updateability.- The crop box is kept within the image.
- Output is capped by the new
curator.curation_max_dimension(default 8192).
5.x also supports Filament 4, so you can move to Curator 5.x without changing Filament.
What's Changed
- fix: expire Glide URLs for media that isn't public by @awcodes in #766
- fix: authorize curation saves and bound the curation's size by @awcodes in #767
- fix: scope the picker's media to the field's settings by @awcodes in #768
Full Changelog: v4.2.2...v4.2.3