What's Changed
Security fixes
Upgrading is recommended for all installations.
- A room member could displace another member's message in everyone's live view. Message elements on the page were identified by a value the sending browser chooses, so a member could post a message that took the place of someone else's message for every member watching the room, and later edits or deletes of that message landed on the other person's message too. A member could also edit one of their own messages so that its text appeared in place of someone else's, under that person's name. Stored messages were never changed, and reloading the page showed the correct conversation. Messages are now identified on the page by their server-assigned id. (GHSA-3v99-4vxh-xg84)
- Banned users kept receiving push notifications. Banning a user signed them out but left their browser or phone subscribed to push notifications, so they went on receiving the room name, sender and text of new direct messages, mentions, and messages in rooms they followed closely. Banned users are no longer sent notifications; lifting the ban restores them. (GHSA-8c6m-5c7f-26fp, #338)
Reported by @frandle331-yh and @namespaceMarcello.
Browser tabs left open across the upgrade may show their own new messages twice until they're reloaded.
Other changes
- Preload only uncached messages and reduce rendering overhead by @dhh in #292
- Document other Campfire implementations and benchmarks by @dhh in #293
- Add Django and Laravel benchmark comparisons by @dhh in #294
- Add Express and refresh implementation benchmarks by @dhh in #315
- Index messages by room and creation time by @namespaceMarcello in #295
- Search for operator words instead of parsing them by @namespaceMarcello in #298
- Wire the inline boost link to the soft keyboard by @rubys in #299
- Ask for JSON when autocompleting people to ping by @rubys in #300
- Check for a second page of messages without counting the room by @namespaceMarcello in #297
- Drop two unmatched closing spans from the flash by @rubys in #302
- Read the newest search matches off the index instead of sorting them all by @namespaceMarcello in #304
- Find the Edge install icon under images/external by @rubys in #301
- Hash fixture passwords at minimum
bcryptcost by @cattekin in #285 - build(deps): bump propshaft from
e49a9detodc979dbby @dependabot[bot] in #287 - build(deps): bump ruby/setup-ruby from 1.324.0 to 1.327.0 in the github-actions group by @dependabot[bot] in #288
- build(deps-dev): bump faker from 3.5.2 to 3.8.0 by @dependabot[bot] in #289
- build(deps-dev): bump selenium-webdriver from 4.35.0 to 4.49.0 by @dependabot[bot] in #291
- Post a webhook reply as an attachment only when the bot answered 200 by @namespaceMarcello in #306
- Update Rails to main by @rubys in #314
- Fan the unread room notice out from a job by @namespaceMarcello in #296
- Find a direct room with one query instead of checking every one by @namespaceMarcello in #310
- Post a message whose attachment can't be previewed instead of failing by @namespaceMarcello in #311
- List one page of account members at a time by @namespaceMarcello in #316
- Query sidebar directs and shared rooms separately by @thomasklemm in #318
- Cache boosts with their message instead of one by one by @namespaceMarcello in #322
- Count unread rooms for push badges once per batch by @namespaceMarcello in #323
- Rewrite a message's search entry only when its body or attachment changes by @namespaceMarcello in #324
- Reuse push connections pinned to the address the guard just approved by @namespaceMarcello in #326
- Bound how long link unfurling can hold a request by @namespaceMarcello in #328
- Delete a room's messages in a job, one transaction each by @namespaceMarcello in #329
- Bound the work of previewing an attachment by @namespaceMarcello in #330
- Show a file in a message's rich text without making its preview on view by @namespaceMarcello in #331
- Create the room and creation time index only where it is missing by @namespaceMarcello in #334
- Find the messages a refresh replaces through an index by @namespaceMarcello in #312
- Render the boosts a message has preloaded instead of querying them again by @namespaceMarcello in #325
Full changelog: v1.5.1...v1.5.2