Skip to content
v22.04.2
6001498
Compare
Choose a tag to compare

Links

Full List of Changes

This release contains the following fixes and changes:

  • Added Persian to language list. (#3426)
  • Updated API docs to detail rate-limit information. (#3423)
  • Updated translations with latest Crowdin changes. (#3418)
  • Fixed broken attachment downloads in environments where PHP output buffering is disabled. (#3415)
  • Fixed LDAP_DUMP_* options throwing error when LDAP details contain binary data. (#3396)
  • Updated PHP dependency versions.
v22.04.1
b1e95eb
Compare
Choose a tag to compare

Links

Full List of Changes

This release contains the following fixes and changes:

  • Fixed issue where a duplicate slash could occur in the URL leading to a 404 page. (#3404)
  • Updated translations with latest changes from Crowdin. (#3402)
v22.04
1a345b7
Compare
Choose a tag to compare

Links

Upgrade Notices

  • Database Changes - This release makes some significant changes to data within the database which may cause the update to take a little longer than usual to run. Please give the update extra time to complete.
  • REST API Page Create/Update Changes - Create & update page requests now have the potential to change the current editor type for that page, depending on the content type sent in the request, if the API user has permission to change the page editor.
  • URL Handling - The way we handle URLs has changed this release to hopefully address some issues in specific scenarios. These changes have been tested and should not affect existing working environments but there's an increased risk this release for setups with more complex URL handling. Please raise an issue or jump into our Discord server if you have any issues with URLs after upgrading.

Full List of Changes

  • Added ability to switch editor types on a per-page basis. (#3387, #458, #369)
  • Added new recycle bin API endpoints. Thanks to @Julesdevops. (#3377, #3372)
  • Added ability to pass diagrams.net configuration options. (#3391)
  • Added Uzbek language option to allow translation, not yet active in the interface. (#3383)
  • Updated translations with latest Crowdin updates. (#3384, #3358)
  • Updated database polymorphic relations to simpler morphmap. (#3395)
  • Updated file handling in many cases to stream data for better efficiency, reduce memory usage and avoid hitting limits. (#3365, #2886)
  • Updated URL handling to be more stable in sub-path scenarios. (#3364, #2765, #2058)
  • Updated content update handling to increment updated_at field, even if only tags are changed. (#3319)
  • Fixed editor Portuguese translation duplication. Thanks to @evandroamaro. (#3373)
  • Fixed API issue where tags would not be applied on API shelf update. (#3370)
  • Fixed development build command lacking Windows/non-bash compatibility. (#3323)
v22.03.1
7233c1c
Compare
Choose a tag to compare

Links

Full List of Changes

This release contains the following fixes and changes:

  • Fixed issue where /settings redirect would lead to wrong location in some scenarios. (#3356)
  • Fixed non-active prevention of custom HTML head content on settings views. (#3355)
  • Updated translations with latest Crowdin changes. (#3354)
  • Updated project PHP dependencies.
v22.03
0333185
Compare
Choose a tag to compare

Links

Upgrade Notices

  • Webhook Data Changes - Properties found at the related_item -> created_by/updated_by/owned_by path of the webhook data will now be an object instead of an ID integer. If you were using these ids you'd now need to access them within the relevant objects. (For example related_item.created_by.id).

Full List of Changes

  • Added support for checkbox tasklists in the WYSIWYG editor. (#3333, #4)
  • Added WYSIWYG control to remove & edit links. (#3276, #3298)
  • Added WYSIWYG Ctrl+Shift+K shortcut to show entity selector popup shortcut in WYSIWYG editor. (#3244, #3298)
  • Added LDAP user group debugging option. (#3345)
  • Added support for the Basque language. (#3296)
  • Updated settings view with a re-organized layout for a less confusing user experience. (#3349, #3221)
  • Updated code block rendering in WYSIWYG to help prevent scroll jumping upon undo/redo. (#3326)
  • Updated translations with latest Crowdin updates. (#3320)
  • Updated webhook data to include details of page/chapter/shelf/book creator/updater/owner. (#3279)
  • Updated webhook data to include revision details on page_update and page_create events. (#3218)
  • Fixed lack of translation support for some editor buttons. (#3342)
  • Fixed incorrect page concatenation in book markdown export. (#3341)
  • Fixed usage of <br> tags within code blocks instead of newlines when using the WYSIWYG editor. (#3327)
  • Fixed image thumbnail generation not taking EXIF rotation data into account. (#1854)
v22.02.3
11a1a6f
Compare
Choose a tag to compare

Security Release

This is a security release that adds better protections against embedded content that could be used in malicious ways. This effectively restricts embedded iframe content in an allow-list approach.

A new ALLOWED_IFRAME_SOURCES option has been added to provide configuration of allowed embed/iframe sources within BookStack pages, and this defaults to a couple of popular services such as YouTube and Vimeo.

Please see this link for more detail regarding this option:

It's advised to upgrade as soon as possible if untrusted users can create or update pages within your BookStack instance.

Thanks to @416e6e61 (Anna) for discovering and reporting this vulnerability via huntr.dev.

Full List of Changes

  • Added iframe allow-list control to prevent a range of malicious uses of untrusted iframe sources. (#3314)
  • Updated translations with latest Crowdin changes. (#3312)
v22.02.2
176a0dc
Compare
Choose a tag to compare

Links

Full List of Changes

This release contains the following fixes and changes:

  • Added cache breaker to WYSIWYG onward loading to prevent plugin errors appearing if cached. (#3303)
  • Updated translations with latest Crowdin changes. (#3301)
  • Updated sidebar fade to be more subtle when in dark mode. (#3203)
  • Fixed WYISWYG editor issue where blank lines would collapse. (#3302)
v22.02.1
08b2a77
Compare
Choose a tag to compare

Links

Full List of Changes

This release contains the following fixes and changes:

  • Updated editor references to avoid caching issue that would prevent WYSIWYG editor from opening. (#3293)
  • Updated code blocks within the editor to be more reliable, especially on first insertion. (#3292)
  • Updated translations with latest changes from Crowdin. (#3291)
v22.02
58b83b6
Compare
Choose a tag to compare

Links

Upgrade Notices

  • PHP Requirements Change - The minimum required version of PHP has changed from 7.3 to 7.4.

Full List of Changes

  • Added collapsible content blocks support to the WYSIWYG editor. (#78, #3260)
  • Added translation support to the WYSIWYG editor. (#1838)
  • Added user management API endpoints. (#3238, #1363, #2701)
  • Changed minimum PHP version from 7.3 to 7.4. (#3245, #3152)
  • Updated translations with latest Crowdin changes. (#3258, #3251, #3259)
  • Updated Korean translations. Thanks to @ististyle. (#3256)
  • Updated TinyMCE WYSIWYG editor to the latest version. (#3247)
  • Improved PDF export rendering of images within tables. (#3190)
  • Fixed potential web console error message when loading the editor. (#2461)
  • Fixed issue where OIDC token failures would not be shown to the user. (#3264)
  • Fixed issue where the editor could jump-scroll to the top after format change on FireFox (#2692)
v21.12.5
d11144d
Compare
Choose a tag to compare

Links

Full List of Changes

This release contains the following fixes and changes:

  • Added text for "file" validation messages to provide better responses in Attachment API validation failures. (#3248)
  • Fixed WYSIWYG editor code block creation across mulitple lines and block elements. Thanks to @Julesdevops. (#3246, #3200)
  • Fixed markdown image data URI extraction failing on large images due to regex match limits. (#3249)
  • Updated translations with latest Crowdin changes. (#3225)