github awcodes/filament-curator v5.5.2

latest releases: v3.7.13, v5.5.3, v4.2.3...
6 hours ago

This release contains security fixes. Upgrading is recommended for every 5.x install, including installs already on 5.5.1. Details will be published in security advisories.

If you're upgrading from 5.5.0 or earlier, also follow the 5.5.1 upgrade step and run php artisan curator:repair-extensions --dry-run, then php artisan curator:repair-extensions.

Changed

  • Upload types are detected from the file's contents.
    • Curator detects an upload's type from the file's own bytes, instead of the type reported for the upload.
    • The accepted-types check and the stored extension both use the detected type.
  • Scriptable types need an exact match.
    • HTML, XML, JavaScript and similar types, and application/octet-stream, are accepted only when listed exactly.
    • A wildcard such as text/* or application/* no longer matches them.
  • SVGs are sanitized before they're written to disk.
    • An SVG that can't be sanitized is rejected, and nothing is stored.
  • Testing your app's uploads:
    • UploadedFile::fake()->create() files are zero-filled, so they're now detected as application/octet-stream and rejected.
    • Use real file contents in upload tests. See Testing uploads.

Fixed

  • Legacy Office files: .doc, .xls and .ppt files keep their type.
  • CSV and calendar files: .csv and .ics files detected as plain text are typed text/csv and text/calendar.
  • Replacements: curator:repair-extensions only deletes an original after its replacement has been written.
  • Custom messages: a custom mimetypes validation message is used again.

Added in #755.

What's Changed

  • fix: detect an upload's type from its own bytes by @awcodes in #755

Full Changelog: v5.5.1...v5.5.2

Don't miss a new filament-curator release

NewReleases is sending notifications on new releases.