You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The .htaccess and Caddy configs now let browsers keep the Admin panel's bundled files for a year, since their names change whenever they do. On Apache, copy the new block from webserver-configs/htaccess.txt into an existing site's .htaccess to get it (getgrav/grav-plugin-admin2#181)
Bugfix
Upgrading Grav from the admin on Windows, for example under Laragon, no longer deletes index.php and leaves the site showing a 404 page (forum)
An upgrade no longer blocks most of the Twig sandbox, such as date, max and batch, on sites whose security.twig_sandbox lists only add entries. Sites an earlier upgrade already did this to get those defaults back.
A fresh install now records the current upgrade level, so its first upgrade no longer reruns fixes meant for older installs.
[security] Updated the bundled DOM sanitizer to 1.0.18, which closes several ways a crafted stylesheet could hide an external resource reference using CSS escapes, such as a backslash-newline line continuation (GHSA-94fv-h7hv-365q).
Commands run by the scheduler, such as a plugin's bin/plugin worker, now run in the same environment as the scheduler, so a site started with bin/grav scheduler --env <host> no longer runs its jobs without the settings in user/env/<host>/config.
With pages.media_route_urls enabled, page files whose names contain a space or an accented character, such as foo bar.pdf or bär.png, no longer return a 404 (#4332)
An image used more than once in Markdown no longer picks up the query parameters, #fragment or style of the earlier uses, and keeps its retina srcset after an earlier use was cropped or resized. Thanks @wakqasahmed (#3567, #4333)
The content XSS check now also flags a javascript: link with a space after the colon, and no longer misses a link when the text elsewhere contains an encoded character it could not decode. Thanks @manus-pi
The private key file user/config/security-private.php is now created readable only by the site's own user, instead of being locked down a moment after it is written. Thanks @shxtterme
Modular sections on Flex-stored pages now re-run their Twig on every request, the same as regular pages already did, so one visitor's output is never reused for another.
On Apache, the file-type rules for images/, assets/, user/, system/ and vendor/ now also apply when a path follows the file name. Upgrading adds the rule to an existing site's .htaccess. Thanks @ma4ter
[security] With image URL actions turned on, the image pixel limit now measures the image each resize actually produces, including one-dimension, percentage and zoomCrop resizes. Thanks @manus-pi
[security] A form defined in page frontmatter now reads config-*@ values through the same filter as page Twig, so it can only show configuration that page Twig may read. Thanks @manus-use and @Hama1cco
[security] Dynamic-data directives in a form defined in page frontmatter now go through the allowed-callable check when the form builds its defaults and validates, not only when it first loads.
[security] Renaming a field while a page-authored Flex form is merged no longer lets it skip the allowed-callable check. Thanks @manus-use