Partial Release notes for 2019.003
UPDATE
See the full release notes over on the help documentation site.
Client Notes (1 - 12)
Developer Notes (13 - 19)
Security Patches (20 - 33)
- Fix keystone javascript error for signed out users
- Fix boilerplate theme link color
- Fix administrator permission error when accessing pockets
- Fix notification sort in React MeBox components (Knowledge Base only)
- Enable category headings in advanced search
- Add themes API v2 resource (Knowledge Base only)
- Add better responsive theme support (Keystone can now be enabled on mobile or desktop separately)
- Fix permission check for api/v2/discussions/search
- Fix Theme-boilerplate and Keystone paddings
- Fix users/me endpoint for Admin=2 users (Already backported and available in 2.8 release)
- Fix user profiles with duplicate user titles
- Fix hitting enter on autocomplete search suggestions causing form submission (Knowledge Base only)
- Normalize reaction Model (DB UPDATE) (Knowledge Base only)
- Make APIv2 upload file check extension case insensitively (Rich Editor fix)
- Add form error component (Knowledge Base only)
- Add fixed scroll position back to the dashboard
- Fix the props & styles of <NextPrevious /> (Knowledge Base only)
- Add toggle-able labels in SiteNav components (Knowledge Base only)
- Add cache options to SQL driver to cache getProviders query response
- Fix permission check when adding a feed
- Fix CSRF when deleting a feed
- Fix reported activity posts displaying as html
- Fix ability to view comment after revoking permission
- Fix adding tags to discussions without proper permission
- Fix discussion permissions when flagging a discussion
- Fix permission check when resolving a discussion
- Fix XSS in Ignore plugin
- Fix stored XSS when deleting a tag
- Fix XSS in username field of InThisDiscussion plugin
- Fix SQL injection in Advanced Search (without Sphinx) using discussionid param
- Fix: Bypassing trusted domains to post links using Right-to-left unicode character
- Fix Bump addon not validating CSRF
- Fix Ignore plugin not authenticating postback
GitHub
- https://github.com/vanilla/vanilla/pull/8473
- https://github.com/vanilla/vanilla/pull/8462
- https://github.com/vanilla/vanilla/pull/8455
- https://github.com/vanilla/vanilla/pull/8452
- https://github.com/vanilla/internal/pull/1828
- https://github.com/vanilla/vanilla/pull/8430
- https://github.com/vanilla/vanilla/pull/8412
- https://github.com/vanilla/internal/pull/1823
- https://github.com/vanilla/vanilla/pull/8387
- https://github.com/vanilla/vanilla/pull/8325
- https://github.com/vanilla/internal/pull/1820
- https://github.com/vanilla/vanilla/pull/8347
- https://github.com/vanilla/vanilla/pull/8454
- https://github.com/vanilla/vanilla/pull/8467
- https://github.com/vanilla/vanilla/pull/8457
- https://github.com/vanilla/vanilla/pull/8469
- https://github.com/vanilla/vanilla/pull/8420
- https://github.com/vanilla/vanilla/pull/8392
- https://github.com/vanilla/addons/pull/655
- https://github.com/vanilla/addons-patches/pull/24
- https://github.com/vanilla/addons-patches/pull/22
- https://github.com/vanilla/vanilla/pull/8398
- https://github.com/vanilla/vanilla-patches/pull/483
- https://github.com/vanilla/vanilla-patches/pull/480
- https://github.com/vanilla/vanilla-patches/pull/479
- https://github.com/vanilla/addons-patches/pull/21
- https://github.com/vanilla/addons-patches/pull/20
- https://github.com/vanilla/vanilla-patches/pull/478
- https://github.com/vanilla/vanilla-patches/pull/477
- https://github.com/vanilla/internal/pull/1817
- https://github.com/vanilla/vanilla-patches/pull/492
- https://github.com/vanilla/addons-patches/pull/25
- https://github.com/vanilla/addons-patches/pull/26
0
Comments
-
Initially I had all of the notes in this comment, but I've moved them to these 2 knowledge base articles:
0 -
Search
Allow selection of
headingtype categories in advanced search.Why Heading and not also Nested/Flat?
0 -
@BrendanParm It seems the release note was incorrect. Those are allowed now too. I've updated the notes.
0 -
It will be 2.8.1 @Adam Charron.
0
This discussion has been closed.