Minor Changes
-
#3875
0a17191Thanks @swissky! - Adds asyncNameoption to external auth providers such as Cloudflare Access. By default, EmDash still replaces a user's name with the provider's name on every authenticated request, so a name edited in the admin is restored on that user's next request. SetsyncName: falseto keep names edited in the admin; the provider's name is then used only when the user is first provisioned.auth: access({ teamDomain: "myteam.cloudflareaccess.com", syncName: false, }),
Patch Changes
-
#3828
609c912Thanks @khoinguyenpham04! - Fixes videos served from/_emdash/api/media/file/not playing in Safari and on iOS, and not seeking past the buffered part in other browsers. With the local, S3, and R2 storage adapters, the media route answersRangerequests with206 Partial Content, or416 Range Not Satisfiablefor a range past the end of the file, and sendsAccept-Ranges: bytes.Custom storage adapters can serve ranges by accepting the optional
options.rangeargument todownload()and settingrangeon the result, as described in the storage interface docs. Adapters that ignore the argument still work: range requests to them receive the whole file, or416for a range past the end of the file. -
#3855
e8b61b3Thanks @emdashbot! - AddsETagandLast-Modifiedvalidators to media file responses and/imagetransforms, and returns304 Not Modifiedwhen a browser'sIf-None-MatchorIf-Modified-Sinceprecondition matches. This lets cached mutable media (images that can be replaced under the same storage key) be revalidated with a single header exchange instead of re-downloaded on every visit. Storage backends now reportlastModifiedwith downloads where available (local filesystem, S3-compatible, and R2). The shortpublic, max-age=0, must-revalidatecache lifetime for images is unchanged, so replacements still appear immediately. -
#3776
9f389fbThanks @emdashbot! - Fixes pluginctx.storage.<collection>.getMany()anddeleteMany()failing on D1 withtoo many SQL variableswhen passed more than 98 ids. Both now accept any number of ids, in trusted and sandboxed plugins alike. -
#3681
cfc7e7dThanks @khoinguyenpham04! - Fixes stored cross-site scripting through the editor toolbar. EmDash inserted the toolbar before the first</body>in a response, but Astro leaves<and>unescaped in attribute values, so content such as an image's alt text could contain</body>and move the toolbar inside that attribute, turning the rest of the text into live markup. The editor toolbar, and the Cloudflare preview and playground toolbars, now go only before the closing body tag of a whole HTML document, never into server island or partial page responses.Before this fix:
- Unless a site set
toolbar: false, an Author's published content could run script for any signed-in Author, Editor, or Admin who viewed it, and a Contributor's draft could do the same to a signed-in Author, Editor, or Admin who previewed it. - With
toolbar: "client", published content could also run script for every visitor. - In preview Workers built with
createPreviewMiddleware, published content could run script for anyone who opened a preview link, whatever thetoolbarsetting.
- Unless a site set
-
Updated dependencies [
d22f62f,b92f2d6,5f69896,04a3d8d,1e275ae,36b46d9,f09797c,cd21162,e3a9de3,0742f27,5b01664,4b2b6e4,47cb798,c4e6737,1e275ae,373446f,1e275ae,0a17191,709dbf4,038e322,b9613bd,6cf612c,8450114,3bcd2cb,9ee7415,36aee2d,da088aa,609c912,a834e75,e2a07ae,e8b61b3,d0c7384,e6fe5d4,c3cc974,07f6f44,2c8c12a,82cea2c,4bc129c,1e275ae,9f389fb,9538600,d8c6d64,aa7cc95,e9cf2c3,766aa29,f223ecd,34f480e,f6ee57e,9451267,3d5a102,0157a63,064f46c,bafa475,7f3093e,3bfd6fc,1e275ae,1bad6d8,4f967ae,d5b8b38,cfc7e7d,f4dc955,550e59b,ea88e8e,740de2b,161ff98,f715431,622a324]:- emdash@1.2.0