This release contains security fixes. Upgrading is recommended for every 5.x install. Details will be published in security advisories.
After upgrading
- Clear caches: purge Glide's cache (
storage/app/.cacheby default) and any CDN in front of your media. - Coming from 5.5.0 or earlier: also run the 5.5.1 step:
php artisan curator:repair-extensions --dry-run- then
php artisan curator:repair-extensions
Changed
- Private media gets expiring Glide URLs.
- Covered:
thumbnail_url,medium_url,large_url,<x-curator-glider>and the table column, for media that isn't public. - These now carry a signed expiry and are served with private cache headers.
- The lifetime comes from the new
curator.temporary_url_expiration(minutes, default 5), whichurlalso uses. - A URL without an expiry only resolves to public media. Public media URLs and caching are unchanged.
- Glide URLs already stored for private media stop working, including ones embedded in rich editor content.
- For private media, a
<x-curator-glider>given a plain path returns 404, so pass the record or its id. - Glide's cache is now kept per disk.
- See Private media.
- Covered:
- Pickers only work with what the field allows.
- The picker and its media panel only list, search, navigate to, insert and act on media that matches the field:
- the field's disk;
- its accepted types (wildcards never match scriptable types);
- its
limitToDirectory()folder and subfolders; - the current tenant.
- Directory matching is case-sensitive, and an empty limited directory lists nothing.
- New selections outside the field's settings fail validation.
- Media already saved on a record keeps loading while it exists and belongs to the tenant. That includes pickers in Repeaters, Builders and Groups.
- The exception is pickers inside conditionally visible components: there, saved media outside the field's settings is dropped.
- See What a picker lists.
- The picker and its media panel only list, search, navigate to, insert and act on media that matches the field:
- The rich editor's media modal uses Curator's disk unless the editor sets its own attachments disk.
- Saving a curation needs the media's
updateability.- The crop box is kept within the image.
- Preset crops that overhang keep their shape, and custom crops that overhang are trimmed.
- Custom crops are capped by the new
curator.curation_max_dimension(default 8192).
What's Changed
- fix: expire Glide URLs for media that isn't public by @awcodes in #763
- fix: authorize curation saves and keep crops within the image by @awcodes in #764
- test: flush Livewire's state before each test by @awcodes in #771
- fix: scope the picker's media to the field's settings by @awcodes in #765
Full Changelog: v5.5.2...v5.5.3