Skip to content

1.0.36

Choose a tag to compare

@rhukster rhukster released this 19 Sep 00:06
· 61 commits to main since this release
0a65379

Bugfix

  • [security] A blanket admin or api grant no longer counts as super user. Permissions inherit from their parent key, so an account given all of api picked up api.super along with it — and super is the flag that decides who can hand super to somebody else. Super must now be granted deliberately, and an invitation can no longer carry it. Ordinary permission inheritance is unchanged. Thanks to @redwolf1919
  • [security] Disabling or deleting an account now ends its API sessions immediately. A session carried its own copy of the account's permissions, and if the account could no longer be read from disk that stale copy was kept rather than refused, so a revoked account stayed usable until its session expired. Thanks to @AlpetGexha
  • The dashboard exposure probe now tests .dat, .txt and .zip files in data, backup and temporary storage, so front proxies serving only some file types are detected. Storage outside the web root is excluded, and the response remains compatible with older Admin2 bundles. getgrav/grav#4316
  • Admin2 package resources, including custom field components, now resolve through Grav's plugins:// and themes:// streams, honoring configured multisite overlay precedence. #43
  • The admin language list, plugin details and AI Translate detection now find plugins outside the default user/plugins folder, such as in multisite setups.