Skip to content

Pad v0.17.2

Latest

Choose a tag to compare

@github-actions github-actions released this 02 Oct 20:19
· 79 commits to main since this release

Security release

Upgrade recommended for all installations. This release fixes several access-control issues found in an internal security review.

  • Invitations: an invitation to an email address now adds an existing account directly only if that account's email is verified. Accepting an invitation code no longer marks an email as verified. Grants by email, email-restricted share links and social-account linking also require a verified address.
  • Documents: restoring an archived document is scoped to the workspace in the URL.
  • Share links: a share link stops resolving while its workspace is deleted, and share responses are no longer cacheable.
  • Webhooks: managing webhooks requires access to the whole workspace, and webhooks don't deliver for a deleted workspace.
  • Deleted collections: an item grant never exposes a deleted collection's items.
  • Errors fail closed: store errors during access checks now deny instead of allowing (authentication, CSRF, live updates, collaboration, item reads and writes). Personal access tokens can no longer read the audit log.
  • Account deletion: the password-free delete path requires a sign-in within the last 10 minutes and refuses API tokens. CLI approval, social unlink and password change now require an interactive session.

Behaviour changes

  • Cloud: an invited person who signs up through an invitation confirms their email before they can make changes. They can read the workspace immediately.
  • Deleting an account without a password requires a recent sign-in; older sessions are asked to sign in again.
  • CLI device approval and social-account unlinking are refused for personal access tokens.

Changelog

Bug fixes

  • 329b931: fix(account): account deletion needs an interactive, recently signed-in session (BUG-3336) (#1733) (@xarmian)
  • aa71cd4: fix(auth): store errors on access decisions fail closed (BUG-3334) (#1730) (@xarmian)
  • 37c3a5e: fix(documents): restore only a document of the URL's workspace (BUG-3335) (#1724) (@xarmian)
  • f0ae689: fix(grants): an item grant never opens a deleted collection (BUG-3333) (#1725) (@xarmian)
  • 3877a31: fix(server): match accounts by email only once the address is verified (#1732) (@xarmian)
  • 28eb5d7: fix(share-links): a link stops resolving while its workspace is deleted (#1726) (@xarmian)
  • b1e8ac4: fix(webhooks): whole-workspace access to manage; no delivery for a deleted workspace (#1727) (@xarmian)