What's Changed
Security:
- [High] Restricted custom API tokens (
minimal=false) can no longer be upgraded to a full-permission session viaPOST /api/auth/renew; renew accepts only web session tokens registered inhashed_tokens(GHSA-6gr6-5qpq-888p) -- thanks @tao0845. - [High] TOTP re-enrollment via
POST /api/auth/otp/generateandPOST /api/auth/otp/verifyno longer allows anonymous callers to replace an existing second factor using only the account password; reset or replace requires an authenticated self or admin session (first-time enrollment without MFA unchanged) (GHSA-qx86-4v5r-26g5) -- thanks @tao0845. - [Low] Public share lyrics and subtitle media routes now honor the share's file-viewer setting, download disable flag, and download limits, matching the public download route (GHSA-p7x3-p5jj-9xfh) -- thanks Yves Soete of Blacksight LLC. @yssoe
New Features:
- Require password change at next login for password-based users: new user setting
requirePasswordChange(user defaults + per-user admin toggle), login blocked until the user sets a new password; bootstrap admins with a generated initial password get this automatically (#2977). Generated bootstrap passwords use a speakableword-xxxxx-xxform (random word from a fixed list plus a 5-character and 2-character code) instead of a long hex string, for easier handoff before the forced change. - Config YAML expands
$VARand${VAR}so values such asuserPassword: "${FILEBROWSER_LDAP_USER_PASSWORD}"work as documented (#3042).
Notes:
- Sidebar navigation tree rows are real hyperlinks: middle-click, Ctrl/Cmd+click, and Shift+click use the browser’s default new-tab or new-window behavior.
- Sidebar source links can now switch between aggregated usage (default) and a root-filesystem-only view via a new "Limit disk usage to source filesystem" toggle.
- [docker] upgraded ffmpeg from 9.0 to 9.0.2
- CLI setup command no longer produces full config, instead a minimal config.yaml with comments.
Bugfixes:
- Fixed slow or broken file listing when
http.baseURLis a subpath (for example/files/): the default source redirect navigated to/files/{source}on top of the app base URL, producing/files/files/{source}and resolving the wrong storage source until the route recovered. - Anonymous visitors on public shares could not play inline video or audio:
GET /public/api/media/streamreturned 403 because view grants were validated before share context was fully hydrated; playback now works when download and the file viewer are allowed (#3041). - Fixed inflated disk usage for sources spanning multiple ZFS datasets (or btrfs subvolumes): shared-pool filesystems are now grouped by pool and counted once, instead of multiplying capacity by the number of mounted datasets (#3025) (#2997) (#2761).
- LDAP
userGroupsmatching now accepts CN-only config values against fullmemberOfDNs and compares case-insensitively, instead of failing the shared auth helper with strict string equality (#3044). - OIDC session expires despite tokenExpirationHours (#3006).
- Media playback becomes stuck after opening a failing media file since v2.0.8-beta (#3031)
All Changes
- added support for env vars in config by @gtsteffaniak in #3047
- Case insensitive match ldap by @gtsteffaniak in #3048
- Fix inflated disk usage on ZFS datasets and btrfs subvolumes; add roo… by @gtsteffaniak in #3035
- fix sidebar behind header on iOS by @Kurami32 in #3060
- Fix token expiration by @gtsteffaniak in #3056
- fix: GHSA-p7x3-p5jj-9xfh - Enforce public share limits on lyrics and subtitle routes. by @gtsteffaniak in #3061
- added feature to reset user password on login by @gtsteffaniak in #3064
- Fix TOTP re-enrollment MFA bypass (GHSA-qx86-4v5r-26g5). by @gtsteffaniak in #3067
- Fix GHSA-6gr6-5qpq-888p: API token session renew by @gtsteffaniak in #3070
- updated cli setup command by @gtsteffaniak in #3071
- Update version match workflow by @gtsteffaniak in #3072
- Fix bugs halloween prompts by @gtsteffaniak in #3076
- make sidebar tree view links native hyperlinks by @gtsteffaniak in #3080
Full Changelog: v2.0.9-beta...v2.0.10-beta