TL;DR
Two security fixes, a round of hardening, and a few bug fixes. Most installs can just upgrade, but skim the upgrade notes if you use the API, embed Fider in an iframe, or use Google Analytics.
Upgrade notes
- API
limit:/api/v1/postsnow capslimitat 1000.limit=allonly works with an API key (Authorization: Bearer …)./api/v1/usersis capped at 100 per page. - Request size: requests over 25 MiB get a
413. You can change this withHTTP_MAX_BODY_SIZE. - Iframes: other sites can't embed Fider in an iframe any more (
frame-ancestors 'self'). - HSTS: sent when Fider handles TLS itself (
SSL_AUTOorSSL_CERT). Not sent if you're behind a proxy. - Google Analytics:
GOOGLE_ANALYTICSnow uses GA4. The old Universal Analytics setup had been silently doing nothing since Google switched it off in 2024. To report per site, registertenantas a custom dimension in GA4.
Security
- GHSA-wjrq-7x2x-9p48: display names and post titles weren't escaped in notification emails and in-app notifications (#1704)
- GHSA-5x23-xx46-6w7r: comments on deleted posts could still be read through the API (#1718)
- Hardening (#1703): request size limits, pagination caps, extra security headers, and stricter image upload checks
Thanks to @kbehroz, @loegaire and @hungtrab for reporting these responsibly.
Fixes
- Code in posts and comments shows
<instead of<, which had been wrong since 2019 (#1698) - Closing a post no longer makes the list jump to the top for a moment (#1708)
- Email subjects no longer lose their first few letters in some cases (#1704)
- Modal accessibility fix (#1709)
Plus some dependency and build housekeeping (#1705, #1706, #1713, #1717).
Full Changelog: v0.38.1...v0.38.2