github getgrav/grav 2.2.2

5 hours ago

Improved

  • The .htaccess and Caddy configs now let browsers keep the Admin panel's bundled files for a year, since their names change whenever they do. On Apache, copy the new block from webserver-configs/htaccess.txt into an existing site's .htaccess to get it (getgrav/grav-plugin-admin2#181)

Bugfix

  • Upgrading Grav from the admin on Windows, for example under Laragon, no longer deletes index.php and leaves the site showing a 404 page (forum)
  • An upgrade no longer blocks most of the Twig sandbox, such as date, max and batch, on sites whose security.twig_sandbox lists only add entries. Sites an earlier upgrade already did this to get those defaults back.
  • A fresh install now records the current upgrade level, so its first upgrade no longer reruns fixes meant for older installs.
  • [security] Updated the bundled DOM sanitizer to 1.0.18, which closes several ways a crafted stylesheet could hide an external resource reference using CSS escapes, such as a backslash-newline line continuation (GHSA-94fv-h7hv-365q).
  • Commands run by the scheduler, such as a plugin's bin/plugin worker, now run in the same environment as the scheduler, so a site started with bin/grav scheduler --env <host> no longer runs its jobs without the settings in user/env/<host>/config.
  • With pages.media_route_urls enabled, page files whose names contain a space or an accented character, such as foo bar.pdf or bär.png, no longer return a 404 (#4332)
  • An image used more than once in Markdown no longer picks up the query parameters, #fragment or style of the earlier uses, and keeps its retina srcset after an earlier use was cropped or resized. Thanks @wakqasahmed (#3567, #4333)
  • The content XSS check now also flags a javascript: link with a space after the colon, and no longer misses a link when the text elsewhere contains an encoded character it could not decode. Thanks @manus-pi
  • The private key file user/config/security-private.php is now created readable only by the site's own user, instead of being locked down a moment after it is written. Thanks @shxtterme
  • Modular sections on Flex-stored pages now re-run their Twig on every request, the same as regular pages already did, so one visitor's output is never reused for another.
  • On Apache, the file-type rules for images/, assets/, user/, system/ and vendor/ now also apply when a path follows the file name. Upgrading adds the rule to an existing site's .htaccess. Thanks @ma4ter
  • [security] With image URL actions turned on, the image pixel limit now measures the image each resize actually produces, including one-dimension, percentage and zoomCrop resizes. Thanks @manus-pi
  • [security] A form defined in page frontmatter now reads config-*@ values through the same filter as page Twig, so it can only show configuration that page Twig may read. Thanks @manus-use and @Hama1cco
  • [security] Dynamic-data directives in a form defined in page frontmatter now go through the allowed-callable check when the form builds its defaults and validates, not only when it first loads.
  • [security] Renaming a field while a page-authored Flex form is merged no longer lets it skip the allowed-callable check. Thanks @manus-use

Don't miss a new grav release

NewReleases is sending notifications on new releases.