This release contains security fixes. Upgrading is recommended for every 5.x install. Details will be published in security advisories.
After upgrading
Check existing media for files stored under an unsafe extension, then repair them:
php artisan curator:repair-extensions --dry-run # report only
php artisan curator:repair-extensions- Renames: the command renames files whose stored extension is unsafe. It prints each rename as
old -> new, so keep the output. - Links: a renamed file's URL changes, so copies of the old link, for example in rich editor content, need updating.
- Left alone: case-only differences such as
.JPGand harmless mismatches are reported but not renamed. Nothing is deleted.
See File types.
Changed
- The media panel's settings are fixed when it opens.
- Its configuration properties are locked, so changing one from the browser (for example with
$wire.set('diskName', …)) now throwsCannotUpdateLockedPropertyException. - If you render the panel yourself, pass everything through
settings. - Folder navigation only goes to the disk root, the configured directory, or folders that hold media.
- Its configuration properties are locked, so changing one from the browser (for example with
- Stored extensions follow the file's detected type.
- The uploaded file's extension is kept when it's a known extension for that type, so
.jpegstays.jpeg. - Zip-based Office and OpenDocument formats keep their extension.
- Otherwise the type's usual extension is used. That means
.txtfor plain text with an uncommon extension, and.binforapplication/octet-stream.
- The uploaded file's extension is kept when it's a known extension for that type, so
- Picker downloads check the Media policy. The picker's download action now uses the media record's own file and requires the policy's
viewability, as the panel's download already did. - Glide no longer sets
base_url. Existing image URLs are unchanged.
Fixed
- Uploads record their tenant: uploads from the picker, the panel and the bulk upload action now record the current tenant when tenancy is enabled.
- Folder named like the Glide route prefix: media stored under such a folder (
curator/by default) is now served correctly. - Escaping: values rendered into JavaScript in the views are now encoded consistently.
- Upload fields: these only save genuine uploads.
- Removed: the unused
CuratorPanel::setMediaForm()method.
Filament 4 users are covered: 5.x serves both majors. Fixes for the 4.x and 3.x lines will follow.
What's Changed
- fix: resolve the picker's download from the media record by @awcodes in #752
- fix: store uploads under the extension of their detected type by @awcodes in #753
- fix: keep the media panel's settings on the server by @awcodes in #754
Full Changelog: v5.5.0...v5.5.1