Skip to content

@emdash-cms/cloudflare@1.2.0

Choose a tag to compare

@emdashbot emdashbot released this 06 Oct 22:10
· 20 commits to main since this release
b5f37c6

Minor Changes

  • #3875 0a17191 Thanks @swissky! - Adds a syncName option to external auth providers such as Cloudflare Access. By default, EmDash still replaces a user's name with the provider's name on every authenticated request, so a name edited in the admin is restored on that user's next request. Set syncName: false to keep names edited in the admin; the provider's name is then used only when the user is first provisioned.

    auth: access({
    	teamDomain: "myteam.cloudflareaccess.com",
    	syncName: false,
    }),

Patch Changes

  • #3828 609c912 Thanks @khoinguyenpham04! - Fixes videos served from /_emdash/api/media/file/ not playing in Safari and on iOS, and not seeking past the buffered part in other browsers. With the local, S3, and R2 storage adapters, the media route answers Range requests with 206 Partial Content, or 416 Range Not Satisfiable for a range past the end of the file, and sends Accept-Ranges: bytes.

    Custom storage adapters can serve ranges by accepting the optional options.range argument to download() and setting range on the result, as described in the storage interface docs. Adapters that ignore the argument still work: range requests to them receive the whole file, or 416 for a range past the end of the file.

  • #3855 e8b61b3 Thanks @emdashbot! - Adds ETag and Last-Modified validators to media file responses and /image transforms, and returns 304 Not Modified when a browser's If-None-Match or If-Modified-Since precondition matches. This lets cached mutable media (images that can be replaced under the same storage key) be revalidated with a single header exchange instead of re-downloaded on every visit. Storage backends now report lastModified with downloads where available (local filesystem, S3-compatible, and R2). The short public, max-age=0, must-revalidate cache lifetime for images is unchanged, so replacements still appear immediately.

  • #3776 9f389fb Thanks @emdashbot! - Fixes plugin ctx.storage.<collection>.getMany() and deleteMany() failing on D1 with too many SQL variables when passed more than 98 ids. Both now accept any number of ids, in trusted and sandboxed plugins alike.

  • #3681 cfc7e7d Thanks @khoinguyenpham04! - Fixes stored cross-site scripting through the editor toolbar. EmDash inserted the toolbar before the first </body> in a response, but Astro leaves < and > unescaped in attribute values, so content such as an image's alt text could contain </body> and move the toolbar inside that attribute, turning the rest of the text into live markup. The editor toolbar, and the Cloudflare preview and playground toolbars, now go only before the closing body tag of a whole HTML document, never into server island or partial page responses.

    Before this fix:

    • Unless a site set toolbar: false, an Author's published content could run script for any signed-in Author, Editor, or Admin who viewed it, and a Contributor's draft could do the same to a signed-in Author, Editor, or Admin who previewed it.
    • With toolbar: "client", published content could also run script for every visitor.
    • In preview Workers built with createPreviewMiddleware, published content could run script for anyone who opened a preview link, whatever the toolbar setting.
  • Updated dependencies [d22f62f, b92f2d6, 5f69896, 04a3d8d, 1e275ae, 36b46d9, f09797c, cd21162, e3a9de3, 0742f27, 5b01664, 4b2b6e4, 47cb798, c4e6737, 1e275ae, 373446f, 1e275ae, 0a17191, 709dbf4, 038e322, b9613bd, 6cf612c, 8450114, 3bcd2cb, 9ee7415, 36aee2d, da088aa, 609c912, a834e75, e2a07ae, e8b61b3, d0c7384, e6fe5d4, c3cc974, 07f6f44, 2c8c12a, 82cea2c, 4bc129c, 1e275ae, 9f389fb, 9538600, d8c6d64, aa7cc95, e9cf2c3, 766aa29, f223ecd, 34f480e, f6ee57e, 9451267, 3d5a102, 0157a63, 064f46c, bafa475, 7f3093e, 3bfd6fc, 1e275ae, 1bad6d8, 4f967ae, d5b8b38, cfc7e7d, f4dc955, 550e59b, ea88e8e, 740de2b, 161ff98, f715431, 622a324]:

    • emdash@1.2.0