github gtsteffaniak/filebrowser v2.0.10-beta

one hour ago

What's Changed

Security:

  • [High] Restricted custom API tokens (minimal=false) can no longer be upgraded to a full-permission session via POST /api/auth/renew; renew accepts only web session tokens registered in hashed_tokens (GHSA-6gr6-5qpq-888p) -- thanks @tao0845.
  • [High] TOTP re-enrollment via POST /api/auth/otp/generate and POST /api/auth/otp/verify no longer allows anonymous callers to replace an existing second factor using only the account password; reset or replace requires an authenticated self or admin session (first-time enrollment without MFA unchanged) (GHSA-qx86-4v5r-26g5) -- thanks @tao0845.
  • [Low] Public share lyrics and subtitle media routes now honor the share's file-viewer setting, download disable flag, and download limits, matching the public download route (GHSA-p7x3-p5jj-9xfh) -- thanks Yves Soete of Blacksight LLC. @yssoe

New Features:

  • Require password change at next login for password-based users: new user setting requirePasswordChange (user defaults + per-user admin toggle), login blocked until the user sets a new password; bootstrap admins with a generated initial password get this automatically (#2977). Generated bootstrap passwords use a speakable word-xxxxx-xx form (random word from a fixed list plus a 5-character and 2-character code) instead of a long hex string, for easier handoff before the forced change.
  • Config YAML expands $VAR and ${VAR} so values such as userPassword: "${FILEBROWSER_LDAP_USER_PASSWORD}" work as documented (#3042).

Notes:

  • Sidebar navigation tree rows are real hyperlinks: middle-click, Ctrl/Cmd+click, and Shift+click use the browser’s default new-tab or new-window behavior.
  • Sidebar source links can now switch between aggregated usage (default) and a root-filesystem-only view via a new "Limit disk usage to source filesystem" toggle.
  • [docker] upgraded ffmpeg from 9.0 to 9.0.2
  • CLI setup command no longer produces full config, instead a minimal config.yaml with comments.

Bugfixes:

  • Fixed slow or broken file listing when http.baseURL is a subpath (for example /files/): the default source redirect navigated to /files/{source} on top of the app base URL, producing /files/files/{source} and resolving the wrong storage source until the route recovered.
  • Anonymous visitors on public shares could not play inline video or audio: GET /public/api/media/stream returned 403 because view grants were validated before share context was fully hydrated; playback now works when download and the file viewer are allowed (#3041).
  • Fixed inflated disk usage for sources spanning multiple ZFS datasets (or btrfs subvolumes): shared-pool filesystems are now grouped by pool and counted once, instead of multiplying capacity by the number of mounted datasets (#3025) (#2997) (#2761).
  • LDAP userGroups matching now accepts CN-only config values against full memberOf DNs and compares case-insensitively, instead of failing the shared auth helper with strict string equality (#3044).
  • OIDC session expires despite tokenExpirationHours (#3006).
  • Media playback becomes stuck after opening a failing media file since v2.0.8-beta (#3031)

All Changes

Full Changelog: v2.0.9-beta...v2.0.10-beta

Don't miss a new filebrowser release

NewReleases is sending notifications on new releases.