Skip to content

Release 14.0.0

Choose a tag to compare

@dkd-kaehm dkd-kaehm released this 01 Sep 18:06
· 12 commits to main since this release

We are happy to release the first stable release of EXT:solr 14.0.0 for TYPO3 14 LTS — and at the same time a security release, carrying the forward-port of the five vulnerabilities fixed in 13.1.4.

📖 Full release notes: Releases 14.0

⚠️ Security

Reported through the TYPO3 Security Team. Installations running 14.0.0-RC1 or earlier should update.

  • CVE-2026-56092 — the fe_group/extendToSubpages-forging listener is removed
  • CVE-2026-56093 — the detail view enforces site and access restrictions
  • CVE-2026-56094 — tx_solr[additionalFilters] can no longer preempt the siteHash or access filter
  • CVE-2026-56095 — multi-value cObjs switch to JSON transport (breaking for third-party content objects that rely on serialize())
  • CVE-2026-56096 — user-controlled Solr query syntax is escaped and field selectors are whitelisted

Requirements

TYPO3 14.3+
PHP 8.2+
Apache Solr 10.0.0
Configset ext_solr_14_0_0
EXT:tika 14.0.0+
EXT:solrfal 14.0.0+

Apache Solr 10 is required — the configset and the managed-resources API were adapted for Jetty 12. Please read the breaking changes before upgrading; a schema update and a full re-index are needed.

Highlights

Collected from the whole 14.0.0-alpha1 → 14.0.0 cycle.

TYPO3 14 and the platform

  • !!! Full TYPO3 14 LTS compatibility, on stable TYPO3 14.3.x
  • !!! Apache Solr 10 / Lucene 10 required — deprecated trie-based dynamic fields removed, ExtractingRequestHandler dropped in favour of EXT:tika 14+
  • !!! solarium/solarium 7.0.0 — removes AbstractQueryBuilder::removeOperator() and removeAlternativeQuery() without alternatives
  • All language files migrated to XLIFF 2.0, event listeners moved to the #[AsEventListener] attribute
  • Scheduler tasks implement getTaskParameters()/setTaskParameters(), so TYPO3 core's SchedulerDatabaseStorageMigration can migrate them — re-run that migration if your EXT:solr tasks were not migrated before this release
  • EXT:install is an optional dependency, static analysis moved to PHPStan 2

Indexing

  • !!! Unified sub-request indexing pipeline — no HTTP round-trips to itself any more, and significantly faster
  • !!! The indexer Index Queue setting and the Index Queue Indexer are retired; indexing runs through IndexingService and the PSR-14 indexing events
  • !!! RecordInsertedEvent introduced, isNewRecord dropped from RecordUpdatedEvent
  • !!! A failed Index Queue item records why it failed, and Index Queue initialization stops at nested site roots
  • New BeforeIndexingSubRequestIsPreparedEvent lets listeners reset state that must not leak between sub-requests
  • Site hash finalized by site identifier — dedicated domain and typo3Context schema fields replace the ad-hoc _stringS fields
  • No c:0 variant and no content leakage on fe_group-restricted pages
  • State no longer leaks between indexing sub-requests: language Context aspect, page title, Context aspects, page cache and the backend web context

Search and frontend

  • !!! jQuery is gone — search, suggest, facet and range controllers rewritten in vanilla JavaScript
  • Site sets registered for all TypoScript templates
  • Spellchecking keeps correctly-spelled terms when offering corrections
  • Suggest fixes: preventable submission, mobile/offcanvas dropdown positioning, routeEnhancer support, several search forms per page
  • Facet URL encoding fixed for spaces with urlParameterStyle=assoc
  • Long Solr GET requests are converted to POST; the PostBigRequest listener became opt-in
  • ASCII folding is applied before stemming in all language schemas
  • Backend module icons in the TYPO3 14 style

Removed API

  • !!! DataUpdateHandler::removeFromIndexAndQueueWhenItemInQueue(), PageIndexer::isPageIndexable(), QueueInitializationServiceAwareInterface and the related Queue API
  • !!! The legacy PageIndexer system, replaced by IndexingInstructions
  • !!! The site hash strategy flag
  • !!! The trailing space in the searchResultClassName and searchResultSetClassName configuration keys
  • !!! Highlighting::getUseFastVectorHighlighter()

What's Changed since 14.0.0-RC1

  • [CLEANUP] Remove unneeded dependency on fluid-styled-content by @dmitryd in #4729
  • Update docs on query.queryFields and query.sortBy by @kitzberger in #4726
  • [BUGFIX] PHPStan issues 2026.08.12 by @dkd-kaehm in #4731
  • [TASK] Make EXT:install an optional dependency by @wazum in #4676
  • [BUGFIX] Convert long Solr GET requests to POST on PSR-14 dispatcher by @wazum in #4631
  • [DOCS] Update links to Apache Solr Reference Guide by @tillhoerner in #4736
  • [BUGFIX] Prevent PHP warning when building the access rootline for uncollected Index Queue pages by @konradmichalik in #4728
  • [BUGFIX] Restore Context aspects after indexing sub-request by @hdj-typoconsult in #4733
  • [TASK] Remove obsolete "addRootLineFields" setting by @tillhoerner in #4735
  • [BUGFIX] fix autosuggestion initialization for multiple search forms on one page by @dkd-kaehm in #4747
  • [BUGFIX] Apply ASCII folding before stemming in all language schemas by @tgaertner in #4741
  • [BUGFIX] Prevent undefined array key warning in SettingsPreviewOnPlug… by @mschwemer in #4686
  • [SECURITY] Fix CVE-2026-56096 — close FVH FieldExistsQuery HTTP 500 oracle by @dkd-kaehm in #4751
  • [TASK] fixes for EXT:solrfal sync by @dkd-kaehm in #4738
  • [TASK] Guard against silently losing a test case by @dkd-kaehm in #4754
  • [TASK] Index pages through the production pipeline in integration tests by @dkd-kaehm in #4755
  • [TASK] Retire the hand-built IndexingInstructions from the integration tests by @dkd-kaehm in #4756
  • [TASK] Retire the indexer Index Queue setting by @dkd-kaehm in #4758
  • [!!!][BUGFIX] Report why an Index Queue item failed, and stop queueing foreign sites' pages by @dkd-kaehm in #4759
  • [!!!][TASK] Remove the Index Queue Indexer, and assert record indexing against the pipeline by @dkd-kaehm in #4760
  • [SECURITY] Forward-port the 13.1.4 security release to TYPO3 14 (CVE-2026-56092 … 56096) by @dkd-kaehm in #4763

New Contributors

Full Changelog: 14.0.0-RC1...14.0.0

Contributors

Like always this release would not have been possible without the help from our awesome community. Here are the contributors to this release (patches, comments, bug reports, reviews, … in alphabetical order):

@amirarends, @un3us, @danilovq, @BastiLu, @beardcoder, @bmack, @pi-phi, @daylightsoftware, @dmitryd, @dkd-lehnebach, @garfieldius, @hdj-typoconsult, @helhum, @hnadler, @jschlier, @konradmichalik, @mschwemer, @dkd-friedrich, @mikelwohlschlegel, @dkd-hauser, @dkd-dobberkau, @kitzberger, @dkd-kaehm, @saschanowak, @sfroemkenjw, @tillhoerner, @tgaertner, @guelzow, @wazum

Also a big thank you to our partners who have already concluded one of our new development participation packages such as Apache Solr EB for TYPO3 14 LTS (Feature):

  • CS2 AG
  • digit.ly
  • fixpunkt werbeagentur gmbh
  • in2code GmbH
  • L.N. Schaffrath DigitalMedien GmbH
  • LOUIS INTERNET GmbH
  • queo GmbH
  • toco3 GmbH & Co. KG
  • Umweltbundesamt GmbH
  • Universität für Musik und darstellende Kunst Wien
  • Universität Regensburg

How to Get Involved

There are many ways to get involved with Apache Solr for TYPO3:

  • Submit bug reports and feature requests on GitHub
  • Ask or help or answer questions in our Slack channel
  • Provide patches through pull requests or review and comment on existing pull requests
  • Go to www.typo3-solr.com or call dkd to sponsor the ongoing development of Apache Solr for TYPO3

Support us by becoming an EB partner:
https://shop.dkd.de/Produkte/Apache-Solr-fuer-TYPO3/

or call:
+49 (0)69 - 2475218 0