github diced/zipline v4.8.0

2 hours ago

Big update, please read the following before updating:

  • You must be on version 4.7.0 before updating to 4.8.0
  • It is recommended but not required to take a database backup, if you don't trust me then take a backup ig
  • If you develop a third-party client that implemeneted the pre-4.8 partial uploads structure, you will need to redo it, check out https://zipline.diced.sh/docs/api/chunked-uploads for docs
  • Docs have also been updated to reflect new stuff such as PGLite support if you want to use that
    • they also include a list of all the errors that the API can return

What's Changed

  • ⚠️ GHSA-rgxm-54cf-whf7, GHSA-7xv9-wr46-j578, GHSA-v938-v8wg-9497, GHSA-wwrw-gq56-7wpj
  • replaced Prisma with Drizzle ORM
    • existing databases are migrated automatically on startup
    • if you're running an older release, update to v4.7.0 and let its migrations finish before updating to v4.8.0
    • back up your database before updating
  • added PGlite support for running Zipline without a separate PostgreSQL server
    • set DATABASE_URL=pglite:///absolute/path/to/database
    • added ziplinectl migrate-pglite to copy an existing PostgreSQL database to PGlite
    • Docker users must mount persistent storage for the database directory
  • added a trusted proxy allowlist
    • if you're using a reverse proxy, CORE_TRUST_PROXY=true alone is no longer enough
    • set CORE_TRUSTED_PROXIES to your proxy's IP addresses or CIDRs, separated by commas, or configure "Trusted Proxies" in Server Settings
    • an empty list ignores forwarded headers, which means clients behind the same proxy share rate limits
    • restart Zipline after changing these settings
  • reworked partial uploads to use single-use continuation tokens
    • custom uploaders must replace partialIdentifier / x-zipline-p-identifier with partialToken / x-zipline-p-token
    • each non-final chunk returns a new token for the next chunk; chunks must be uploaded sequentially
    • corrected Content-Range handling to use inclusive end offsets
    • valid continuation requests no longer count against the upload rate limit
    • improved cleanup of failed and interrupted uploads
  • redesigned the Pending Files modal
    • added a "Clear completed" button to remove completed entries without deleting uploaded files
  • added an iTake configuration generator for macOS
  • fixed file uploads on Windows
  • fixed filename encoding and handling of special characters in file URLs
  • fixed code previews stripping parts of source files before syntax highlighting #1136
  • fixed invalid or unreachable OIDC avatar URLs causing errors
  • fixed database configuration when using DATABASE_* variables instead of DATABASE_URL
  • fixed disabled MIME-type policies not being enforced when editing a file's type
  • fixed extension restrictions being bypassed through casing and double extensions
  • fixed concurrent requests and raw file access bypassing maximum view limits
  • fixed shortened URL view-limit handling to match files
  • fixed OpenAPI schemas used to generate the API documentation
  • switched development tooling to TypeScript 7, oxlint, and oxfmt
  • added automated tests

Pulls Merged

New Contributors

Full Changelog: v4.7.0...v4.8.0

Don't miss a new zipline release

NewReleases is sending notifications on new releases.