Skip to content

5.11.4

Latest

Choose a tag to compare

@github-actions github-actions released this 01 Oct 15:49
ad1fd33
  • Added craft\services\Users::destroyOtherSessions().
  • Setting up a two-step verification method now destroys the user’s other sessions.
  • Deleting a passkey now requires an elevated session.
  • Fixed a bug where an uninformative error message could be shown when saving a draft that no longer passed validation. (#19674)
  • Fixed a bug where the Assets index page could display the wrong assets and subfolders after reloading the browser tab. (#19689)
  • Fixed a bug where Matrix fields set to the “Cards”, “Card grid”, or “Index” view modes weren’t respecting craft\fields\Matrix::EVENT_DEFINE_ENTRY_TYPES. (#19685)
  • Fixed a bug where the attribute() Twig function was allowed within sandboxed Twig environments, even if it wasn’t listed in allowedFunctions.
  • Fixed a bug where Twig array access with a false key could return the wrong value when Dev Mode was disabled.
  • Fixed an error that could occur when adding a new site to a draft, if it contained multiple levels of nested content. (#18281)
  • Fixed a bug where dragged items weren’t getting dropped where expected, if their container had scrolled during the drag operation. (#19721)
  • Fixed a bug where publicly-registered users weren’t getting activated and logged in immediately, if email verification wasn’t required but the password was deferred. (#19610)
  • Fixed a bug where changing an entry’s type could cause values for fields shared by both entry types to be lost. (#19737)
  • Fixed an error that could occur when running the setup/php-session-table and setup/db-cache-table commands. (#19742)
  • Fixed an infinite loop that could occur when editing nested Matrix entries in Blocks view. (#19756)
  • Fixed a bug where filtering elements by textual params or conditions could only work if the param/condition value was all-lowercase. (#19781)
  • Fixed a high-severity RCE vulnerability. (GHSA-hq78-cm2m-h24h)
  • Fixed a low-severity RCE vulnerability. (GHSA-6m9q-c5q4-3732)
  • Fixed a low-severity authorization bypass vulnerability. (GHSA-j2r3-x468-c6j5)
  • Fixed a low-severity XSS vulnerability. (GHSA-q2rx-mr36-8rh5)