CI Report:
N/A
LinuxServer Changes:
Full Changelog: 2.67.0-ls204...2.68.0-ls205
Remote Changes:
Compatible with PHP 8.2 to 8.5
Features
- Dropdowns: visible label length increased to 180 char + scroll to selected element on open (#6222)
- Reports: sticky first column in horizontal tables (#6216)
- Better duration input handling on all duration fields (#6210)
- Shorter duration entry: Interpret ints < 10 as hours and >= 10 as minutes (#6146)
- User locale: default system setting + format examples in dropdown (#6186)
- API: added endpoint to update invoice (#6184)
- User profile: move "copy to clipboard" button to the left (#6184)
- Customer listing: added optional column to show first the line 1 of the address (#6184)
- Weekly-Hours: button to filter timesheets in "All times" view by the selected user and date-range (#6184)
- Translations update from Hosted Weblate (#6190)
Timesheet Batch-Update
- Show form error inline instead of flashing it (#6184)
- Show amount of timesheets (#6184)
- Validate each timesheet during update (#6184)
- Support the optional
breakfield (#6184)
Bugfixes
- SAML/LDAP - fix invalid Avatar prevents login (#6223)
- Fix URLs with untranslated locales using subregions (broken user profiles) (#6184)
- API: invoice payment date is a date, not a date-time (BC) (#6184)
Security
- Timesheet batch-update: throw if timesheet may not be edited, instead of skipping it (#6184)
- Check team access is possible before checking
*_team_xand*_teamlead_xpermissions (#6184) - Check that the user can view the requested team via API (#6184)
- Validate team access on batch-update form for project and activity (#6184) - thanks @Humbertosp
- Unify API and UI checks for the timesheet PATCH action (#6184) - thanks @devzephyr
- Improve 2FA auth on remember-me accounts (#6184) - thanks @AzureADTrent
- Bind
password-resetandsystem-accountflags to "roles" permission (#6184) - thanks @AzureADTrent - Improve wizard route detection to prevent skipped wizards (#6184) - thanks @rach1tarora
- Remove Docker entrypoint debug tracing - thanks @AlpetGexha @Xylakant
- Disable password reset if
TRUSTED_HOSTSis not configured (#6226)
Maintenance
- API: preload team members users and preferences to avoid N+1 (#6189)
- Dispatch event on invoice status change (#6184)
- Simplify adding translated API forms via form extension and interface (#6184)
- Cleanup swiss translations (#6184)
- Clarify we do NOT accept raw AI output in security reports (#6184)
- Clarify permission check as code comment to prevent further invalid security reports (#6184)
You can read more about all security reports here or grab this RSS feed to get notified about new published advisories.
Involved in this release: @Arslan-TR, @hacklschorsch, @kevinpapst, @AgenteGabrielofc, aspopovic, Bartosz Sobótkowski, @flytothehighest, @mapi68, @milotype and @stysus