Minor Changes
-
#3440
03b6b3bThanks @swissky! - Adds two settings to the Navigation section of the content type editor:- Icon: the Phosphor icon name shown for the collection in the admin sidebar and in command palette navigation, such as
calendar-blank. A sidebar folder shows the icon of the first collection in it that declares one. A name that does not resolve falls back to the collection's default icon. - Hide from navigation: removes the collection's sidebar entry, its command palette link, and its dashboard quick action. The collection stays reachable by URL, the API, and plugins. Collections that were already hidden now also drop out of the command palette.
API and seed files
The manifest now publishes each collection's
icon. Collection icon names are now trimmed and limited to 64 characters in the schema API and the MCP collection tools, and limited to 64 characters in seed files, so longer values are rejected. Sending an emptyiconclears the stored icon. - Icon: the Phosphor icon name shown for the collection in the admin sidebar and in command palette navigation, such as
-
#3440
03b6b3bThanks @swissky! - Adds anadmin.quickCreatecollection setting that removes the collection's "new entry" quick action from the admin dashboard. Set it tofalsein a seed file or through the schema API, or turn off "Quick action on the dashboard" in the content type editor's Navigation section. Collections without the setting keep their quick action. A schema API update replaces the wholeadminobject, so include any existingadmin.listColumnsin the same request. -
#1939
2410395Thanks @swissky! - Adds a core update notice to the admin dashboard. When a newer EmDash version is available, admins see a dismissible banner with a link to the release notes. The banner names the newest release that has been public on npm for at least 24 hours.The check is on by default: the server sends a GET request to
https://registry.npmjs.org/emdashat most once a day, in the background, with no site data. To wait longer before a release is announced, for example to match pnpm'sminimumReleaseAge, or to turn the check off:emdash({ updateCheck: { minimumReleaseAge: "7d" } }); // a duration string or seconds emdash({ updateCheck: false });
The banner reads
GET /_emdash/api/admin/core-update, which requires the newupdates:readpermission (admins only). -
#3394
38d200dThanks @ttmx! - Adds thebylines:readplugin capability, which lets plugins read public byline profiles and the bylines credited on content entries throughctx.bylines.ctx.bylinesprovidesget()and cursor-paginatedlist()for profiles, plusgetEntriesBylines()for credits.getEntriesBylines()resolves up to 100 entries of one collection in a single call, so a search indexer or feed plugin can attach author names to a page ofctx.content.list()results:const page = await ctx.content.list("posts", { limit: 100 }); const credits = await ctx.bylines.getEntriesBylines( "posts", page.items.map((entry) => entry.id), );
Credits match what the site renders: the credits assigned in the editor, or the author's linked byline, marked
source: "inferred", when an entry has none. They resolve at the entry's own locale. Profiles omit the linked user account, guest flag, and byline custom field values.The capability is independent of
content:readandusers:read. It is available to native plugins and to sandboxed plugins on Cloudflare Worker Loader and Node.js workerd. Installation and update consent list it as a new permission. -
#3495
9358edeThanks @ascorbic! - Addsadmin.footerLabelfor customizing or hiding the label beside the version in the admin sidebar. The label defaults to"EmDash"instead of reusing the configured site name. Set it to a string to use another label, or set it tofalseto show the version alone.
Patch Changes
-
#3513
f465247Thanks @swissky! - Shows the language's name next to its code under "Content language" in the content editor sidebar, for example "Italiano IT", when the admin itself is not translated into that language. It showed the code twice before, as in "IT IT". -
#3512
70589bcThanks @swissky! - Shows relative times in the admin's language, such as "vor 5 Minuten" in German, in the dashboard's recent activity and the revision history. They were in English for every admin language before. English wording changes slightly: "5 mins ago" is now "5 minutes ago" and "1 day ago" is now "yesterday". -
#3466
6e58b48Thanks @solaymanhaider! - Adds Bengali (বাংলা) to the admin UI with a complete translation catalog. The locale is selectable from the language picker, and the date picker shows Bengali month and day names. -
#3493
148ff3eThanks @MA2153! - Fixes bulk term assignment only working with the built-intagtaxonomy. Editors can now add a term from any taxonomy, such as a category or a custom taxonomy, to up to 50 posts from a collection's bulk-actions bar or from that taxonomy's page. When several taxonomies apply to a collection, the dialog asks which one to use. ThePOST /_emdash/api/taxonomies/bulk-tagendpoint now accepts a term from any taxonomy, and matches only entries in the collections that use that taxonomy. -
#3467
1ba8fcbThanks @khoinguyenpham04! - Updates the Bylines admin page with a full-width profile list and a focused create/edit dialog. Editors can see guest and account-link status at a glance while keeping search, custom fields, translations, and deletion in the same workflow. -
#3441
cc91805Thanks @swissky! - Fixes the Features column on the Content Types list so theseobadge matches the collection's SEO setting. Collections with SEO turned on in the editor now show the badge, and collections with SEO turned off no longer show one. -
#3492
d583dfdThanks @kgni! - Adds Danish (Dansk) translations for the admin UI. The locale is selectable from the language picker. -
#3450
db76eaeThanks @emdashbot! - Fixes content type icons in the admin Content Types list so they keep a 1:1 aspect ratio when a collection description forces the Name cell to wrap. -
#2898
8b1b585Thanks @scottbuscemi! - Fixes rich text image settings so caption, alt text, tooltip, size, and alignment edits persist when authors click back into the post. Captions and tooltip titles also round-trip independently, so clearing a caption no longer restores it from the tooltip text. -
#3439
ff61df9Thanks @emdashbot! - Fixes WordPress WXR imports failing partway through large exports. The admin now imports taxonomy terms, content, and reusable blocks in bounded requests while preserving translation links and the complete import summary.Direct API clients can continue using a single request for small exports. Larger exports return
WXR_IMPORT_TOO_LARGEand must use the chunkedtaxonomy,content, andfinalizephases. -
#3470
ccd80cbThanks @khoinguyenpham04! - Updates the admin Menus pages with scannable navigation cards, a clearer create-menu dialog, and a menu editor with a labeled back link and matching add-action buttons. -
#3509
b84ea22Thanks @ascorbic! - Fixes the Portable Text editor saving dotted filenames and identifiers such asREADME.mdandsetup.shas external links when authors type or paste them. -
#3431
72f10bdThanks @danielmlr! - Fixes the header of Block Kit plugin panels in the content editor sidebar so it lines up with the Revisions and Outline sections. The section's reorder handle no longer covers the panel's content or, while the panel is collapsed, the section below it. -
#3491
bf1aa14Thanks @ascorbic! - Fixes the publication-date dialog so editors can retry a date-only change after another writer updates the entry, without overwriting content fields. -
#2966
bc32000Thanks @danielmlr! - Fixes an entry's publication date saving without a warning when someone else changed the entry after the editor loaded it. The date change is now refused like any other save based on a stale read, and the editor shows its conflict notice with the option to save over the newer version. -
#3325
c23009dThanks @ascorbic! - Fixes an open redirect in the admin login page and the logout, magic-link sign-in, and dev-bypass routes: a?redirect=value containing a tab, carriage return, or line feed (for example/%09/evil.example) could send the browser to another site. Redirect values that contain control characters are now ignored. -
#3475
42bf9f5Thanks @danielmlr! - Fixes reference fields showing "No references selected." when an entry is reopened in the admin within a minute of an autosave, publish, or schedule change. Adding a reference after such a reopen no longer removes the entries that were already saved. -
#3471
d96f039Thanks @khoinguyenpham04! - Updates the Sections library to use compact thumbnails for reusable sections, showing a supplied preview image when available and a section icon otherwise. Search, source filtering, creation, and actions now follow the other admin pages. At narrower widths, the section editor places details beneath the content so form fields stay within their panel. -
#3327
f796444Thanks @ascorbic! - Fixes stored cross-site scripting throughurlcontent fields. EmDash previously acceptedjavascript:anddata:values, so a theme rendering<a href={entry.data.website}>could run an attacker's script on the site origin. Aurlfield, including one inside a repeater or block, now accepts only these values:http:andhttps:URLsmailto:andtel:links- site-relative paths such as
/about, and fragments such as#contact
The REST API, MCP tools, site transfers, WordPress imports, and the admin editor reject any other value with a validation error. Seeds and plugin content updates also reject unsafe schemes and path forms that browsers resolve to another site, including
//example.comand/\\example.com. The admin editor now accepts relative paths, fragments,mailto:, andtel:and keeps URL input left-to-right in every locale.Existing entries are not changed. An unsafe stored value is still returned by queries, and saving or duplicating that entry fails until the field is corrected.
sanitizeHref()andisSafeHref()now reject unsafe protocol-relative, backslash-prefixed, and control-character forms when rendering older content. -
#3303
d8ea3fcThanks @ascorbic! - Fixes a denial-of-service in public URL routing: a collection URL pattern with several placeholders in one path segment, such as/{a}{b}{c}{d}{e}x, let a single crafted request tie up the server for seconds whileresolveEmDashPath()matched it.Collection URL patterns now allow at most one placeholder per path segment.
/{year}/{month}/{slug}.htmland/p-{id}/{slug}are still valid, but/{year}{month}/{slug}and/{slug}-{id}are rejected when a collection is created or its pattern is changed through the admin, the REST API, the MCPschema_update_collectiontool, or a seed. Seed files with such a pattern fail validation before anything is applied. The admin's collection editor shows the problem next to the URL Pattern field.If a collection already has a pattern that breaks this rule, it keeps working for generating links in menus, sitemaps and redirects, but
resolveEmDashPath()no longer matches it, and the site logs a warning naming the collection. REST, MCP and admin updates that send the stored pattern back unchanged still succeed. Give each placeholder its own segment (for example, change/{slug}-{id}to/{id}/{slug}) to route those entries again. -
#3445
b2ce32cThanks @swissky! - Fixes admin sign-in silently returning to the login page when no Astro session driver is configured. Signing in with a passkey, magic link, invite link, or signup link now fails with aSESSION_UNAVAILABLEerror explaining that a session driver is required, and OAuth sign-in returns to the login page with the same explanation, instead of reporting success without keeping the user signed in. Magic links, invite links, and signup links stay usable for a retry.astro devandastro buildalso warn when the driver is missing or sessions are disabled withsession: false. The Node, Cloudflare, and Netlify adapters configure a driver automatically; on other adapters, such as Vercel, configuresession.driverinastro.config.mjs. -
Updated dependencies [
f2f9119,2e943ff,38d200d,38d200d,895fb69]:- @emdash-cms/blocks@0.42.0
- @emdash-cms/plugin-types@0.5.0
- @emdash-cms/registry-lexicons@0.7.0
- @emdash-cms/registry-client@0.7.0