A release worth taking promptly: 4.4.0 and 4.4.1 could make login impossible on a host without the sodium extension.
Fixed
- Upgrading to 4.4.0 could make login impossible on a host without the sodium extension, with
Folders error: HTTP Token mismatchafter every attempt.openssl_get_cipher_methods()lists ciphers the provider will not actually use, and on OpenSSL 3 that includesaes-256-cbc-hmac-sha1, which is the shipped default. Encryption fell back to xxtea, correctly, but the hardening added in 4.4.0 then refused xxtea wheneveropenssl_decrypt()merely existed, so the server rejected the tokens it had just minted and no session could be established. The cipher is now tried rather than looked up, a working one is used when the configured one is not, and the refusal asks whether openssl can really be used. Affected installs are signed out once and move to proper encryption. Reported by @realsimix (#121) - Save in Nextcloud selected a folder, turned its spinner and wrote nothing. The plugin called
\OCP\Files::getStorage(), which Nextcloud deprecated in 14 and has since removed, so the call threw and the save failed silently. The same call was in the "Save as .eml" path. Reported by @BlackIkeEagle (#116) - The Nextcloud file picker put a
selectbutton on every folder row and floated its checkboxes out of line. Folders now carry a radio confirmed from the footer, file names are clickable labels, and the rows line up. Reported by @lvarnava (#117) - A plugin updated to a build-numbered version kept reporting the version before it and offered the same update for ever. The release-time bump wrote the new version into
packages.jsonbut packaged anindex.phpstill declaring the old one, and the admin panel reads the installed version from that constant. Reported by @ivnmad (#119) - Several callers passed HTTP headers as an associative array, which reached curl as bare values and were sent malformed and dropped: the integrity check, the breach lookup, which therefore travelled without its API key, and the CardDAV upload path, which answered
403 supported-address-data. Thanks to @FathiBenNasr (#124) - Only the first
data-*attribute was stripped from a composed message, because removing an attribute while iterating a liveDOMNamedNodeMapends the iteration. The rest went out in sent mail and saved drafts. Thanks to @FathiBenNasr (#126) - An empty contact list on either side of a CardDAV sync deleted everything on the other. An empty list is more often a fault than an intent, so deletions in that direction are now skipped and logged. Thanks to @FathiBenNasr (#125)
- The ics-viewer panel never appeared on invitations from Evolution or Exchange, which put the calendar part inline and repeat it as
application/icsrather than attachingtext/calendar. Thanks to @FathiBenNasr (#127)
Security
- The two-factor-auth plugin keeps its TOTP secret sealed rather than in clear, and backup codes only as hashes. A code from an already-accepted 30 second step is refused, and five failures in fifteen minutes lock that account's second factor for fifteen. Existing enrolments and printed backup codes carry over untouched. Thanks to @FathiBenNasr (#128)
- The avatars plugin answered without a session and fetched a URL chosen by whoever asked, with the SSRF gate switched off, then cached the result under any address. Only instances with
bimiorfaviconenabled were affected; both default to off
Changed
- The Debian package gains a signed
tachyon_<version>-1_all.changesfile for importing into reprepro or aptly, declaresphp-xml, without which a clean Debian 13 install fails the integrity check, and requires PHP 8.2 or later.php-openssl,php-exifandphp-sodiumare dropped, none of them being real packages on Debian. Thanks to @dionysius (#129) - The two-factor secret is now tied to
APP_SALT. Lose or regenerateSALT.php, by restoring a backup without it for instance, and every user loses their second factor with no way back but an administrator clearing their record. Before this the secret was stored in clear and survived such a change. Back upSALT.phpwith the data directory