Repository navigation
v2.0.0-stable #3105
gtsteffaniak
announced in
Announcements
v2.0.0-stable
#3105
Replies: 3 comments 8 replies
|
Migration went almost perfectly but somehow the OIDC redirect_uri switched from https to http "The redirect_uri 'http://file.mydomain.com/api/auth/oidc/callback' is not registered for this client." Where can I fix that ? |
2 replies
|
The migration went fine but the previews seem to be broken. When hovering overr a folder a popup comes with "Popup image" and the broken image and in the log there is a error 500 "/api/resources/preview?path=%2FXXXXXXXX%2F&key=1786905624624&source=XXXXXXXX&inline=true&size=xlarge&atPercentage=25" with "this item does not have a preview" but in the info hasPreview is true. |
4 replies
|
I'm unable to sign in with OIDC anymore. Authentik: "Redirect URI Error". |
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What's Changed
This version represents the most significant change to date. It requires both a database migration and config structural changes. See the migration guide for step-by-step upgrade instructions, About v2.0.0 for a full summary.
Also, consider enabling "analytics" in admin settings which will help me populate an anonymous public dashboard for everyone to see. Currently, theres 60 deployments details populated from beta, so after a percentage of you enable this in staging there should be plenty to make the dashboard useful and available. No private information is used, you can see exactly what data is sent in the UI.
Breaking Changes:
GET /api/rawandGET /public/api/rawdownload routes — use/api/resources/downloadinstead./share/…URL redirect to/public/share/…— use/public/share/…directly.sourcesearch api param (usesources), barescopepaths withoutsourceName:prefix, andglob/useGlobaliases (useuseWildcard).config.conditionals, source-levelindexingIntervalMinutes(indexing always uses adaptive scheduling), and deprecated rule fieldsfileNames/folderNames/ top-levelhidden— useconfig.ruleswithfileName,folderName, andignoreHiddenon rules. See Exclusion rules.userDefaultsconfig formats (nested and flat) — use the config migration tool to convert before upgrading.PUT /api/usersmoved to the more appropriatePATCHmethod and requires specifyingwhichin the body. Blank orallvalues are rejected.serverconfig key moved tohttpconfig key. See HTTP settings.http.trustedHeaders(v1.5.x list) removed — usehttp.trustProxyHeaders: truewhen behind nginx, Traefik, or Caddy. When enabled, FileBrowser honorsX-Forwarded-Host,X-Forwarded-Proto,X-Forwarded-For, andX-Real-IPfor client IP, cookies, OIDC callbacks, WebAuthn, share URLs, rate limiting, and activity logs. Default isfalse(direct connection values). The config migration tool converts v1trustedHeaderslists totrustProxyHeaders: true. See Reverse proxy and HTTP trustProxyHeaders.FILEBROWSER_DATABASEenvironment variable — useFILEBROWSER_DATABASE_PATHinstead. See Environment variables and Server settings./api/media/stream. See API reference.user set <username> --password [value]anduser promote <username>;set -u username,passwordis deprecated. See CLI reference.Security:
belongsTo. Auth signing keys are now persisted in the application database and JWT validation fails closed when no key is configured. (GHSA-8f9r-wg7w-pfw) (Auth signing key and token migration #2987) Thanks @d3do-23 and @whoamis3c.POST /api/auth/renew(GHSA-6gr6-5qpq-888p) -- thanks @tao0845.allowReplacements=falsenow reject overwrites when clients sendoverride=true. (GHSA-3846-gh75-gp3m) Thanks @d3do-23integrations.office.secretJWT and require the document key to match the cached editor session; document downloads re-validate redirect targets against the configured document-server host (SSRF); public shares withenableOnlyOffice=falsereject/office/*requests server-side.admin/admingenerate a random initial password and log it once (Fresh install of beta leaves well known bootstrap admin account #2977).stateto an HttpOnly cookie and rejects tampered callbacks; login/logout/session-expiry redirects reject open-redirect targets, and signup sends credentials in a JSON body instead of query parameters.New Features:
settings > access managementviewpermission is automatically set to true unless explicitly set to false. See Access control overview.F4shortcut to refresh the current directory and metadata (Improve more the playback queue + metadata caching #2600).X-OC-Mtimeheader for clients that support it (add webdav X-OC-Mtime header support #2626). See WebDAV docs.COPYpreserves modification times only for files, is limitation we have with webdav.userDefaultsseeds SQLite on first run; only fields explicitly set in config stay locked in Settings → User defaults (other defaults remain editable)settings > user management > user defaults.settings > access management.FILEBROWSER_DATABASEis removed (startup fails if set). UseFILEBROWSER_DATABASE_PATH(defaultfilebrowser.sqlite) orserver.database.pathin config. See Environment variables and Server settings.user setwith--password(inline value, interactive prompt on TTY, or piped stdin);user promotefor admin grant without password reset. See CLI reference.requirePasswordChange(user defaults + per-user admin toggle). Bootstrap admins with a generated initial password get this automatically (#2977). Generated bootstrap passwords use a speakableword-xxxxx-xxform.theme-colorsync on dark-mode toggle, and edge-to-edge safe-area layout for notched devices (Mobile and PWA styling improvements #2625) (Add PWA maskable icons and safe-area foundation for notched devices. #2869) -- thanks @APatenaudeinitCLI command, which creates a minimal commented config.yaml instead of a full config (Add cli init command #2957)$VARand${VAR}so values such asuserPassword: "${FILEBROWSER_LDAP_USER_PASSWORD}"work (auth: methods: ldap: userPassword: "${FILEBROWSER_LDAP_USER_PASSWORD}" doesn't take the value of environment variable #3042).Notes:
./filebrowser),setup,version, andset rulesyntax unchanged; see CLI docsuser.idhas been moved to a backend property and all frontend apis now query users by username. Swagger has been updated. See API reference./api/media/streamis audio/video only (range-based chunking). Non-media inline viewing usesGET /api/resources/view. Both endpoints use the sameviewTokenfrom file metadata. See API reference.X-Renew-Tokenheader handling removed.defaultEnablednow means the source is always added to users on startup and login.showHidden, causing sync clients to delete local hidden files #3004)/api/share/directAPI. (Direct download link is not protected by password #2888)/api/resources/downloadand/public/api/resources/downloadreturn HTTP 404 for missing files/directories instead of 500 (/api/resources/downloadreturns status 500 when file is not found #2981);GET /api/resourcesreturns 400 whenpathis missing or empty (GET /api/resourcesreturns 500 whenpathis empty or omitted #2801).Bugfixes:
groupsClaimis always requested and falls back to UserInfo; the verified ID-token identifier is preserved on fallback; sessions respecttokenExpirationHours(OIDC session expires despite tokenExpirationHours #3006).userGroupsmatching accepts CN-only values against fullmemberOfDNs and is case-insensitive (The LDAP group name in config.yaml is case-sensitive and doesn't accept only CN #3044)..rafthumbnail preview; unsupported image preview formats return HTTP 415 instead of 500.~) source paths expand properly.http.baseURLis a subpath.busy_timeouton every pooled connection; busy errors no longer reported as success or empty cache results.Full Changelog: v1.5.8-stable...v2.0.0-stable
This discussion was created from the release v2.0.0-stable.
All reactions