Links
Full List of Changes
This release contains the following fixes and changes:
- Added Persian to language list. (#3426)
- Updated API docs to detail rate-limit information. (#3423)
- Updated translations with latest Crowdin changes. (#3418)
- Fixed broken attachment downloads in environments where PHP output buffering is disabled. (#3415)
- Fixed
LDAP_DUMP_*options throwing error when LDAP details contain binary data. (#3396) - Updated PHP dependency versions.
Links
Full List of Changes
This release contains the following fixes and changes:
Links
Upgrade Notices
- Database Changes - This release makes some significant changes to data within the database which may cause the update to take a little longer than usual to run. Please give the update extra time to complete.
- REST API Page Create/Update Changes - Create & update page requests now have the potential to change the current editor type for that page, depending on the content type sent in the request, if the API user has permission to change the page editor.
- URL Handling - The way we handle URLs has changed this release to hopefully address some issues in specific scenarios. These changes have been tested and should not affect existing working environments but there's an increased risk this release for setups with more complex URL handling. Please raise an issue or jump into our Discord server if you have any issues with URLs after upgrading.
Full List of Changes
- Added ability to switch editor types on a per-page basis. (#3387, #458, #369)
- Added new recycle bin API endpoints. Thanks to @Julesdevops. (#3377, #3372)
- Added ability to pass diagrams.net configuration options. (#3391)
- Added Uzbek language option to allow translation, not yet active in the interface. (#3383)
- Updated translations with latest Crowdin updates. (#3384, #3358)
- Updated database polymorphic relations to simpler morphmap. (#3395)
- Updated file handling in many cases to stream data for better efficiency, reduce memory usage and avoid hitting limits. (#3365, #2886)
- Updated URL handling to be more stable in sub-path scenarios. (#3364, #2765, #2058)
- Updated content update handling to increment updated_at field, even if only tags are changed. (#3319)
- Fixed editor Portuguese translation duplication. Thanks to @evandroamaro. (#3373)
- Fixed API issue where tags would not be applied on API shelf update. (#3370)
- Fixed development build command lacking Windows/non-bash compatibility. (#3323)
Links
Full List of Changes
This release contains the following fixes and changes:
Links
Upgrade Notices
- Webhook Data Changes - Properties found at the
related_item -> created_by/updated_by/owned_bypath of the webhook data will now be an object instead of an ID integer. If you were using these ids you'd now need to access them within the relevant objects. (For examplerelated_item.created_by.id).
Full List of Changes
- Added support for checkbox tasklists in the WYSIWYG editor. (#3333, #4)
- Added WYSIWYG control to remove & edit links. (#3276, #3298)
- Added WYSIWYG
Ctrl+Shift+Kshortcut to show entity selector popup shortcut in WYSIWYG editor. (#3244, #3298) - Added LDAP user group debugging option. (#3345)
- Added support for the Basque language. (#3296)
- Updated settings view with a re-organized layout for a less confusing user experience. (#3349, #3221)
- Updated code block rendering in WYSIWYG to help prevent scroll jumping upon undo/redo. (#3326)
- Updated translations with latest Crowdin updates. (#3320)
- Updated webhook data to include details of page/chapter/shelf/book creator/updater/owner. (#3279)
- Updated webhook data to include revision details on page_update and page_create events. (#3218)
- Fixed lack of translation support for some editor buttons. (#3342)
- Fixed incorrect page concatenation in book markdown export. (#3341)
- Fixed usage of
<br>tags within code blocks instead of newlines when using the WYSIWYG editor. (#3327) - Fixed image thumbnail generation not taking EXIF rotation data into account. (#1854)
Security Release
This is a security release that adds better protections against embedded content that could be used in malicious ways. This effectively restricts embedded iframe content in an allow-list approach.
A new ALLOWED_IFRAME_SOURCES option has been added to provide configuration of allowed embed/iframe sources within BookStack pages, and this defaults to a couple of popular services such as YouTube and Vimeo.
Please see this link for more detail regarding this option:
- https://www.bookstackapp.com/docs/admin/security/#iframe-src-control
- ("Iframe Source Control" section)
It's advised to upgrade as soon as possible if untrusted users can create or update pages within your BookStack instance.
Thanks to @416e6e61 (Anna) for discovering and reporting this vulnerability via huntr.dev.
Full List of Changes
Links
Full List of Changes
This release contains the following fixes and changes:
Links
Full List of Changes
This release contains the following fixes and changes:
Links
Upgrade Notices
- PHP Requirements Change - The minimum required version of PHP has changed from 7.3 to 7.4.
Full List of Changes
- Added collapsible content blocks support to the WYSIWYG editor. (#78, #3260)
- Added translation support to the WYSIWYG editor. (#1838)
- Added user management API endpoints. (#3238, #1363, #2701)
- Changed minimum PHP version from 7.3 to 7.4. (#3245, #3152)
- Updated translations with latest Crowdin changes. (#3258, #3251, #3259)
- Updated Korean translations. Thanks to @ististyle. (#3256)
- Updated TinyMCE WYSIWYG editor to the latest version. (#3247)
- Improved PDF export rendering of images within tables. (#3190)
- Fixed potential web console error message when loading the editor. (#2461)
- Fixed issue where OIDC token failures would not be shown to the user. (#3264)
- Fixed issue where the editor could jump-scroll to the top after format change on FireFox (#2692)
Links
Full List of Changes
This release contains the following fixes and changes:
- Added text for "file" validation messages to provide better responses in Attachment API validation failures. (#3248)
- Fixed WYSIWYG editor code block creation across mulitple lines and block elements. Thanks to @Julesdevops. (#3246, #3200)
- Fixed markdown image data URI extraction failing on large images due to regex match limits. (#3249)
- Updated translations with latest Crowdin changes. (#3225)