Big update, please read the following before updating:
- You must be on version
4.7.0before updating to4.8.0 - It is recommended but not required to take a database backup, if you don't trust me then take a backup ig
- If you develop a third-party client that implemeneted the pre-4.8 partial uploads structure, you will need to redo it, check out https://zipline.diced.sh/docs/api/chunked-uploads for docs
- Docs have also been updated to reflect new stuff such as PGLite support if you want to use that
- they also include a list of all the errors that the API can return
What's Changed
- ⚠️ GHSA-rgxm-54cf-whf7, GHSA-7xv9-wr46-j578, GHSA-v938-v8wg-9497, GHSA-wwrw-gq56-7wpj
- replaced Prisma with Drizzle ORM
- existing databases are migrated automatically on startup
- if you're running an older release, update to v4.7.0 and let its migrations finish before updating to v4.8.0
- back up your database before updating
- added PGlite support for running Zipline without a separate PostgreSQL server
- set
DATABASE_URL=pglite:///absolute/path/to/database - added
ziplinectl migrate-pgliteto copy an existing PostgreSQL database to PGlite - Docker users must mount persistent storage for the database directory
- set
- added a trusted proxy allowlist
- if you're using a reverse proxy,
CORE_TRUST_PROXY=truealone is no longer enough - set
CORE_TRUSTED_PROXIESto your proxy's IP addresses or CIDRs, separated by commas, or configure "Trusted Proxies" in Server Settings - an empty list ignores forwarded headers, which means clients behind the same proxy share rate limits
- restart Zipline after changing these settings
- if you're using a reverse proxy,
- reworked partial uploads to use single-use continuation tokens
- custom uploaders must replace
partialIdentifier/x-zipline-p-identifierwithpartialToken/x-zipline-p-token - each non-final chunk returns a new token for the next chunk; chunks must be uploaded sequentially
- corrected
Content-Rangehandling to use inclusive end offsets - valid continuation requests no longer count against the upload rate limit
- improved cleanup of failed and interrupted uploads
- custom uploaders must replace
- redesigned the Pending Files modal
- added a "Clear completed" button to remove completed entries without deleting uploaded files
- added an iTake configuration generator for macOS
- fixed file uploads on Windows
- fixed filename encoding and handling of special characters in file URLs
- fixed code previews stripping parts of source files before syntax highlighting #1136
- fixed invalid or unreachable OIDC avatar URLs causing errors
- fixed database configuration when using
DATABASE_*variables instead ofDATABASE_URL - fixed disabled MIME-type policies not being enforced when editing a file's type
- fixed extension restrictions being bypassed through casing and double extensions
- fixed concurrent requests and raw file access bypassing maximum view limits
- fixed shortened URL view-limit handling to match files
- fixed OpenAPI schemas used to generate the API documentation
- switched development tooling to TypeScript 7, oxlint, and oxfmt
- added automated tests
Pulls Merged
- refactor: prisma to drizzle-orm by @diced in #1128
- fix: windows file uploads by @justadityaraj in #1138
- fix: #1136 by @justadityaraj in #1137
- feat: add iTake generator (macOS only) by @SerStars in #1134
- fix: derive core.databaseUrl from DATABASE_* variables by @Gauvino in #1140
New Contributors
- @justadityaraj made their first contribution in #1138
- @SerStars made their first contribution in #1134
- @Gauvino made their first contribution in #1140
Full Changelog: v4.7.0...v4.8.0