Security
This release comes from a review of the whole codebase. Updating is recommended for every install, especially ones where non-admin users or other people's machines are connected.
- Text from client machines is escaped in the web interface (GHSA-jwq4-qmhw-54mm). Output a client reports, such as plugin test results, could carry markup that ran in the browser of the person viewing it. Agent-reported text and user-set names are now escaped wherever the page builds HTML. Thanks to @Artur12555 for the report.
- Access control:
- A plan can only use its own client's plugin configurations.
- Repository passphrases show only to users who manage that client's repositories.
- Retrying a job needs the permission that job needs.
- Pausing plans over the API needs Manage Plans.
- Only admins can place repositories on a Remote SSH host.
- A changed role takes effect at once, and deleted users are signed out.
- "Require 2FA" also applies to API login.
- Password reset links use the server's configured address instead of the request's.
- Email notifications are sent as plain text, and client output can no longer change their format or contents.
- Stricter checks on data sent by clients (file catalog entries, archive names, log sizes) and on the server's privileged helper, notification URLs and storage paths.
- Dependencies: league/commonmark 2.10.3, phpseclib 3.0.57.
Changes
- The client page no longer shows Add Repository or Add Backup Plan to users without permission to finish them (#525).
No agent change; agent stays 2.98.0.