github getfider/fider v0.38.2

2 hours ago

TL;DR

Two security fixes, a round of hardening, and a few bug fixes. Most installs can just upgrade, but skim the upgrade notes if you use the API, embed Fider in an iframe, or use Google Analytics.

Upgrade notes

  • API limit: /api/v1/posts now caps limit at 1000. limit=all only works with an API key (Authorization: Bearer …). /api/v1/users is capped at 100 per page.
  • Request size: requests over 25 MiB get a 413. You can change this with HTTP_MAX_BODY_SIZE.
  • Iframes: other sites can't embed Fider in an iframe any more (frame-ancestors 'self').
  • HSTS: sent when Fider handles TLS itself (SSL_AUTO or SSL_CERT). Not sent if you're behind a proxy.
  • Google Analytics: GOOGLE_ANALYTICS now uses GA4. The old Universal Analytics setup had been silently doing nothing since Google switched it off in 2024. To report per site, register tenant as a custom dimension in GA4.

Security

  • GHSA-wjrq-7x2x-9p48: display names and post titles weren't escaped in notification emails and in-app notifications (#1704)
  • GHSA-5x23-xx46-6w7r: comments on deleted posts could still be read through the API (#1718)
  • Hardening (#1703): request size limits, pagination caps, extra security headers, and stricter image upload checks

Thanks to @kbehroz, @loegaire and @hungtrab for reporting these responsibly.

Fixes

  • Code in posts and comments shows < instead of &lt;, which had been wrong since 2019 (#1698)
  • Closing a post no longer makes the list jump to the top for a moment (#1708)
  • Email subjects no longer lose their first few letters in some cases (#1704)
  • Modal accessibility fix (#1709)

Plus some dependency and build housekeeping (#1705, #1706, #1713, #1717).

Full Changelog: v0.38.1...v0.38.2

Don't miss a new fider release

NewReleases is sending notifications on new releases.