github umputun/remark42 v1.18.0
Version 1.18.0

2 hours ago

Upgrade Notes

  • with the bolt store, a session's site must exactly match a configured --site value, and login requests for unknown sites are rejected. Remote-store deployments keep accepting any site here, as the remote store decides which sites exist #2262 @paskal
  • remark_config.__colors__ is deprecated in favour of custom_properties. It keeps working, and custom_properties wins when both set the same key #2253 @Bluetegu

Security Fixes

  • the delete-me approval page could run a requesting user's markup in the admin's session, and the token in a delete-me link could be used to act as the requesting user. The page now renders the server's response and errors as text, and delete-me tokens are rejected as sessions. Site-scoped admin sessions can now process deletion tokens only for their own site #2262 @paskal
  • the token in an email unsubscribe link could be used to sign in as that email address. Email login now accepts only the confirmation token it issued itself, and the token is no longer written to the log on login errors. go-pkgz/auth is at v2.3.1 #2265 @paskal

New Features

  • remark_config.custom_properties overrides the widget's CSS custom properties from the embedding page. --font-family is the supported one, so the widget can match the host page's font #2253 @Bluetegu
  • the reply form has its own placeholder, "Your reply here" in English. Other locales keep their comment placeholder until translated #2235 @Bluetegu
  • Dutch #2252 @ftechmax and Icelandic #2254 @birgirsteinn locales, and corrections to the Italian one #2259 @AlexzanDev

Bug Fixes

  • the demo, counter and last-comments pages under /web use the first configured site when served by the binary, as the docker image already did. On an instance not serving site remark they failed with "site not found" and opening them signed the reader out #2264 @paskal
  • a 403 response no longer signs the reader out. The widget cleared its session on any 403, including one for another site on the same host. Sign-out now also completes when the server refuses the logout request #2264 @paskal
  • /api/v1/last is cached per user. One reader's votes could be shown to others, and a voter kept seeing the state from before the vote #2263 @paskal
  • an admin is recognised right after anonymous, email or Telegram sign-in, without a page reload #2260 @pkvach
  • the email subscription token field uses dark theme colours in the dark theme #2255 @pkvach

Don't miss a new remark42 release

NewReleases is sending notifications on new releases.