Skip to content

@emdash-cms/admin@0.42.0

Choose a tag to compare

@emdashbot emdashbot released this 27 Sep 20:24
· 26 commits to main since this release
67ff362

Minor Changes

  • #3440 03b6b3b Thanks @swissky! - Adds two settings to the Navigation section of the content type editor:

    • Icon: the Phosphor icon name shown for the collection in the admin sidebar and in command palette navigation, such as calendar-blank. A sidebar folder shows the icon of the first collection in it that declares one. A name that does not resolve falls back to the collection's default icon.
    • Hide from navigation: removes the collection's sidebar entry, its command palette link, and its dashboard quick action. The collection stays reachable by URL, the API, and plugins. Collections that were already hidden now also drop out of the command palette.

    API and seed files

    The manifest now publishes each collection's icon. Collection icon names are now trimmed and limited to 64 characters in the schema API and the MCP collection tools, and limited to 64 characters in seed files, so longer values are rejected. Sending an empty icon clears the stored icon.

  • #3440 03b6b3b Thanks @swissky! - Adds an admin.quickCreate collection setting that removes the collection's "new entry" quick action from the admin dashboard. Set it to false in a seed file or through the schema API, or turn off "Quick action on the dashboard" in the content type editor's Navigation section. Collections without the setting keep their quick action. A schema API update replaces the whole admin object, so include any existing admin.listColumns in the same request.

  • #1939 2410395 Thanks @swissky! - Adds a core update notice to the admin dashboard. When a newer EmDash version is available, admins see a dismissible banner with a link to the release notes. The banner names the newest release that has been public on npm for at least 24 hours.

    The check is on by default: the server sends a GET request to https://registry.npmjs.org/emdash at most once a day, in the background, with no site data. To wait longer before a release is announced, for example to match pnpm's minimumReleaseAge, or to turn the check off:

    emdash({ updateCheck: { minimumReleaseAge: "7d" } }); // a duration string or seconds
    emdash({ updateCheck: false });

    The banner reads GET /_emdash/api/admin/core-update, which requires the new updates:read permission (admins only).

  • #3394 38d200d Thanks @ttmx! - Adds the bylines:read plugin capability, which lets plugins read public byline profiles and the bylines credited on content entries through ctx.bylines.

    ctx.bylines provides get() and cursor-paginated list() for profiles, plus getEntriesBylines() for credits. getEntriesBylines() resolves up to 100 entries of one collection in a single call, so a search indexer or feed plugin can attach author names to a page of ctx.content.list() results:

    const page = await ctx.content.list("posts", { limit: 100 });
    const credits = await ctx.bylines.getEntriesBylines(
    	"posts",
    	page.items.map((entry) => entry.id),
    );

    Credits match what the site renders: the credits assigned in the editor, or the author's linked byline, marked source: "inferred", when an entry has none. They resolve at the entry's own locale. Profiles omit the linked user account, guest flag, and byline custom field values.

    The capability is independent of content:read and users:read. It is available to native plugins and to sandboxed plugins on Cloudflare Worker Loader and Node.js workerd. Installation and update consent list it as a new permission.

  • #3495 9358ede Thanks @ascorbic! - Adds admin.footerLabel for customizing or hiding the label beside the version in the admin sidebar. The label defaults to "EmDash" instead of reusing the configured site name. Set it to a string to use another label, or set it to false to show the version alone.

Patch Changes

  • #3513 f465247 Thanks @swissky! - Shows the language's name next to its code under "Content language" in the content editor sidebar, for example "Italiano IT", when the admin itself is not translated into that language. It showed the code twice before, as in "IT IT".

  • #3512 70589bc Thanks @swissky! - Shows relative times in the admin's language, such as "vor 5 Minuten" in German, in the dashboard's recent activity and the revision history. They were in English for every admin language before. English wording changes slightly: "5 mins ago" is now "5 minutes ago" and "1 day ago" is now "yesterday".

  • #3466 6e58b48 Thanks @solaymanhaider! - Adds Bengali (বাংলা) to the admin UI with a complete translation catalog. The locale is selectable from the language picker, and the date picker shows Bengali month and day names.

  • #3493 148ff3e Thanks @MA2153! - Fixes bulk term assignment only working with the built-in tag taxonomy. Editors can now add a term from any taxonomy, such as a category or a custom taxonomy, to up to 50 posts from a collection's bulk-actions bar or from that taxonomy's page. When several taxonomies apply to a collection, the dialog asks which one to use. The POST /_emdash/api/taxonomies/bulk-tag endpoint now accepts a term from any taxonomy, and matches only entries in the collections that use that taxonomy.

  • #3467 1ba8fcb Thanks @khoinguyenpham04! - Updates the Bylines admin page with a full-width profile list and a focused create/edit dialog. Editors can see guest and account-link status at a glance while keeping search, custom fields, translations, and deletion in the same workflow.

  • #3441 cc91805 Thanks @swissky! - Fixes the Features column on the Content Types list so the seo badge matches the collection's SEO setting. Collections with SEO turned on in the editor now show the badge, and collections with SEO turned off no longer show one.

  • #3492 d583dfd Thanks @kgni! - Adds Danish (Dansk) translations for the admin UI. The locale is selectable from the language picker.

  • #3450 db76eae Thanks @emdashbot! - Fixes content type icons in the admin Content Types list so they keep a 1:1 aspect ratio when a collection description forces the Name cell to wrap.

  • #2898 8b1b585 Thanks @scottbuscemi! - Fixes rich text image settings so caption, alt text, tooltip, size, and alignment edits persist when authors click back into the post. Captions and tooltip titles also round-trip independently, so clearing a caption no longer restores it from the tooltip text.

  • #3439 ff61df9 Thanks @emdashbot! - Fixes WordPress WXR imports failing partway through large exports. The admin now imports taxonomy terms, content, and reusable blocks in bounded requests while preserving translation links and the complete import summary.

    Direct API clients can continue using a single request for small exports. Larger exports return WXR_IMPORT_TOO_LARGE and must use the chunked taxonomy, content, and finalize phases.

  • #3470 ccd80cb Thanks @khoinguyenpham04! - Updates the admin Menus pages with scannable navigation cards, a clearer create-menu dialog, and a menu editor with a labeled back link and matching add-action buttons.

  • #3509 b84ea22 Thanks @ascorbic! - Fixes the Portable Text editor saving dotted filenames and identifiers such as README.md and setup.sh as external links when authors type or paste them.

  • #3431 72f10bd Thanks @danielmlr! - Fixes the header of Block Kit plugin panels in the content editor sidebar so it lines up with the Revisions and Outline sections. The section's reorder handle no longer covers the panel's content or, while the panel is collapsed, the section below it.

  • #3491 bf1aa14 Thanks @ascorbic! - Fixes the publication-date dialog so editors can retry a date-only change after another writer updates the entry, without overwriting content fields.

  • #2966 bc32000 Thanks @danielmlr! - Fixes an entry's publication date saving without a warning when someone else changed the entry after the editor loaded it. The date change is now refused like any other save based on a stale read, and the editor shows its conflict notice with the option to save over the newer version.

  • #3325 c23009d Thanks @ascorbic! - Fixes an open redirect in the admin login page and the logout, magic-link sign-in, and dev-bypass routes: a ?redirect= value containing a tab, carriage return, or line feed (for example /%09/evil.example) could send the browser to another site. Redirect values that contain control characters are now ignored.

  • #3475 42bf9f5 Thanks @danielmlr! - Fixes reference fields showing "No references selected." when an entry is reopened in the admin within a minute of an autosave, publish, or schedule change. Adding a reference after such a reopen no longer removes the entries that were already saved.

  • #3471 d96f039 Thanks @khoinguyenpham04! - Updates the Sections library to use compact thumbnails for reusable sections, showing a supplied preview image when available and a section icon otherwise. Search, source filtering, creation, and actions now follow the other admin pages. At narrower widths, the section editor places details beneath the content so form fields stay within their panel.

  • #3327 f796444 Thanks @ascorbic! - Fixes stored cross-site scripting through url content fields. EmDash previously accepted javascript: and data: values, so a theme rendering <a href={entry.data.website}> could run an attacker's script on the site origin. A url field, including one inside a repeater or block, now accepts only these values:

    • http: and https: URLs
    • mailto: and tel: links
    • site-relative paths such as /about, and fragments such as #contact

    The REST API, MCP tools, site transfers, WordPress imports, and the admin editor reject any other value with a validation error. Seeds and plugin content updates also reject unsafe schemes and path forms that browsers resolve to another site, including //example.com and /\\example.com. The admin editor now accepts relative paths, fragments, mailto:, and tel: and keeps URL input left-to-right in every locale.

    Existing entries are not changed. An unsafe stored value is still returned by queries, and saving or duplicating that entry fails until the field is corrected. sanitizeHref() and isSafeHref() now reject unsafe protocol-relative, backslash-prefixed, and control-character forms when rendering older content.

  • #3303 d8ea3fc Thanks @ascorbic! - Fixes a denial-of-service in public URL routing: a collection URL pattern with several placeholders in one path segment, such as /{a}{b}{c}{d}{e}x, let a single crafted request tie up the server for seconds while resolveEmDashPath() matched it.

    Collection URL patterns now allow at most one placeholder per path segment. /{year}/{month}/{slug}.html and /p-{id}/{slug} are still valid, but /{year}{month}/{slug} and /{slug}-{id} are rejected when a collection is created or its pattern is changed through the admin, the REST API, the MCP schema_update_collection tool, or a seed. Seed files with such a pattern fail validation before anything is applied. The admin's collection editor shows the problem next to the URL Pattern field.

    If a collection already has a pattern that breaks this rule, it keeps working for generating links in menus, sitemaps and redirects, but resolveEmDashPath() no longer matches it, and the site logs a warning naming the collection. REST, MCP and admin updates that send the stored pattern back unchanged still succeed. Give each placeholder its own segment (for example, change /{slug}-{id} to /{id}/{slug}) to route those entries again.

  • #3445 b2ce32c Thanks @swissky! - Fixes admin sign-in silently returning to the login page when no Astro session driver is configured. Signing in with a passkey, magic link, invite link, or signup link now fails with a SESSION_UNAVAILABLE error explaining that a session driver is required, and OAuth sign-in returns to the login page with the same explanation, instead of reporting success without keeping the user signed in. Magic links, invite links, and signup links stay usable for a retry. astro dev and astro build also warn when the driver is missing or sessions are disabled with session: false. The Node, Cloudflare, and Netlify adapters configure a driver automatically; on other adapters, such as Vercel, configure session.driver in astro.config.mjs.

  • Updated dependencies [f2f9119, 2e943ff, 38d200d, 38d200d, 895fb69]:

    • @emdash-cms/blocks@0.42.0
    • @emdash-cms/plugin-types@0.5.0
    • @emdash-cms/registry-lexicons@0.7.0
    • @emdash-cms/registry-client@0.7.0