Skip to content

Commit 207846a

Browse files
boutellmyovchevBoDonkeyharounThomas Boutell
authored
ready for 4.32.0 release (#5513)
* Bump CLI dependencies (#5383) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> * Native browser shortcuts work again (#5384) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> * merge back the thanks (#5388) * Postgres (#5365) * postgres experimental WIP * astonishingly, all mocha tests of apostrophe pass with this * mocha tests pass, actual sites work * lint clean * listDatabases support, but changes are coming * wip * dump and restore updates * backpressure, adequate handling of ObjectId for our needs (becomes its hex representation) * mild performance optimization * profiling * testing issue resolved * refactored to db-connect module, introduced sqlite adapter * sqlite WIP * debugging * programmatic API for dump/restore/copy dbs * linting, documentation * MIT license * text ranking is more accurate, documentation is more complete * good full text search for sqlite * updates for compatibility with the rest of the public and private modules, plus a few fixes to genuinely ambiguous tests * requirements found by testing private modules * fixes from full cypress run * eslint passing * restore permissions * maximize atomicity * bug fixes * * exit properly when asset tests fail * "npm test" tests all three adapters * ignore claude-tools in eslint * postgres and sqlite-inclusive ci matrix attempt * clean up logs * We hit github's limit on total configurations because every package gets its own matrix. Solve that with grouping: * apostrophe core * All regular ecosystem packages other than core * non-database-requiring packges * mongodb-specific packages This will probably speed it up too because it won't have to spin up a container a bazillion times. * hardened the asset tests, made them less timing sensitive, fixed a bad commit resulting from the way they dodgily patch themselves without a robust cleanup mechanism * fix a root cause of asset test instability * log mess * implemented missing $size operator * test compatibility * advanced permission uses regex in $in * regex in $in * .db() should not make false promises in plain postgres mode, it should fail * ability to specify a default adapter * obsolete file * put escapeHost back where it belongs * dead code removal, test cleanup * emulate-mongo-3-driver only needed in db-connect * no claude logs in repo (tools are welcome) * * shared aggregation implementation, other shared things * optimize $match when it is the first step in aggregation, don't fetch the whole collection 😜 * multipostgres listDatabases() and .db() should return and expect "fully qualified virtual database names," e.g. physical_db_name-schemaname * vanilla postgres should not attempt to use .db() with alternate names in tests * documentation corrections * documentation errors * listDatabases and documentation corrections * more edge cases revealed by latest work from Miro * anchored prefix regexps are optimized documentation improvements * * matchesQuery in the aggregation cursor implementation doesn't throw on unrecognized operators. It should, and it should support the same mongodb operators that the regular find() path does in postgres/sqlite (our official subset), unless there is an extraordinary reason not to. * Similarly, the main query implementation for normal queries should throw on unrecognized operators if it doesn't already. * The dump/restore programmatic APIs in db-connect concern me. These involve returning the entire database as a string, which could exhaust memory. This impacts both utilities and also copyDatabase(). Could these APIs return and expect async iterators instead of strings? * The test "anchored regex on an indexed field uses a btree index search" runs explain on a query that's hardcoded in the test. Instead these SQL based adapters should expose a means to get the SQL for a query, so it can be directly tested. Otherwise this test proves nothing as changes to the adapter accumulate in future. * Why is this test searching for "at least 1" and not exactly 1? it('should find documents with null value', async function() { const docs = await db.collection('test').find({ value: null }).toArray(); // MongoDB matches both null and missing fields with { value: null } expect(docs.length).to.be.at.least(1); }); * What is the maximum size of a db-connect document in the postgres and sqlite adapters? * Update the copyright year in db-connect/LICENSE.md to 2025. * The db-connect README mentions: sqlite://:memory: What happens if you try to use .db('some-name') with that? I think it would be best to just not support throwaway in-memory sqlite databases because I doubt anyone would intentionally store a website in one. * do not swallow dump/restore errors on indexes * cover how to run the utilities * fix detection of source * separate sanitization for index names * regex prefix safety * pnpm --------- Co-authored-by: Thomas Boutell <boutell@vcs.trox.local> * forgot to include a changeset (#5390) * ignore inline table array as draggable ui for windows (#5392) * Layout focus orchestration (#5393) * Pro 9405 remove hreflang (#5395) * Remove hreflang generation and update README * Add changeset * Changeset update * Pro 9406 base url (#5396) * Removes `seoSiteCanonicalUrl` * Update tests and remove missed log * Change semver level * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures * Pro 9405 remove hreflang (#5395) * Remove hreflang generation and update README * Add changeset * Changeset update * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed * Layout editable gap (#5397) * a11y fixes (#5401) * clarifications (#5403) * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * Merge commit from fork * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * mergeback (#5409) * Latest merge prerelease 2026 05 (#5404) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> (cherry picked from commit 9f458b5d9544d33239a0971b0050fff8bffe028a) * Bump CLI dependencies (#5383) (cherry picked from commit a5e1a4a35d01e09cbfd2c503370c95a8c2490867) * Native browser shortcuts work again (#5384) (cherry picked from commit b9b32bdd446add927c75d85e44d0a26814ba62b0) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments (cherry picked from commit 08845c5f23d95ead552ab9743a878daf997793a1) * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> (cherry picked from commit d45e27f6d66cd25fde0cf9c7199ee9d014fa1518) * merge back the thanks (#5388) (cherry picked from commit f3501f4de0448d4d0f8a01a1db4dc2fcf52c6218) * ignore inline table array as draggable ui for windows (#5392) (cherry picked from commit b360b05e8d4e479a36fcae45a5a6dbf820b8fba3) * Layout focus orchestration (#5393) (cherry picked from commit 77a2968206b0208883ff45de37feb43ba0b5d5b1) * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures (cherry picked from commit 008417fa9814dba4899b53b9394778dbd46ccf3c) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed (cherry picked from commit e9b3bac692315414da47fe05202e8854dd31d7ee) * Layout editable gap (#5397) (cherry picked from commit bc8f7bed381d4462a082976dd92b8d7f28180a95) * a11y fixes (#5401) (cherry picked from commit 2e2f3b4b46301fc81c46200f837e794b247a9aef) * clarifications (#5403) (cherry picked from commit 13f2c69f219a47f82972d8fa9036deddd84223dc) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Latest security merge (#5407) * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * Merge commit from fork * Merge commit from fork * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * release only (changelogs formatted) (#5408) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * mergeback (#5414) * Latest merge prerelease 2026 05 (#5404) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> (cherry picked from commit 9f458b5d9544d33239a0971b0050fff8bffe028a) * Bump CLI dependencies (#5383) (cherry picked from commit a5e1a4a35d01e09cbfd2c503370c95a8c2490867) * Native browser shortcuts work again (#5384) (cherry picked from commit b9b32bdd446add927c75d85e44d0a26814ba62b0) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments (cherry picked from commit 08845c5f23d95ead552ab9743a878daf997793a1) * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> (cherry picked from commit d45e27f6d66cd25fde0cf9c7199ee9d014fa1518) * merge back the thanks (#5388) (cherry picked from commit f3501f4de0448d4d0f8a01a1db4dc2fcf52c6218) * ignore inline table array as draggable ui for windows (#5392) (cherry picked from commit b360b05e8d4e479a36fcae45a5a6dbf820b8fba3) * Layout focus orchestration (#5393) (cherry picked from commit 77a2968206b0208883ff45de37feb43ba0b5d5b1) * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures (cherry picked from commit 008417fa9814dba4899b53b9394778dbd46ccf3c) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed (cherry picked from commit e9b3bac692315414da47fe05202e8854dd31d7ee) * Layout editable gap (#5397) (cherry picked from commit bc8f7bed381d4462a082976dd92b8d7f28180a95) * a11y fixes (#5401) (cherry picked from commit 2e2f3b4b46301fc81c46200f837e794b247a9aef) * clarifications (#5403) (cherry picked from commit 13f2c69f219a47f82972d8fa9036deddd84223dc) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Latest security merge (#5407) * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * Merge commit from fork * Merge commit from fork * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * release only (changelogs formatted) (#5408) * allow oembetter to be released (#5412) * release oembetter 1.2.0 (#5413) * release oembetter 1.2.0 * left commit --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Fix focus trap on the last element in a modal (#5406) * Fix focus trap on the last element in a modal * Fix trap escaping edge cases * Fix import-export noise (#5399) * remove noise, switch to utils debug * Fix tests * Introduce debug option * changelog * Fix test sorting issue * A11y fixes part 3 (#5416) * Fix editor modal a11y issues * Fix manager a11y problems * Fix page manager a11y problems * fix media manager a11y issues * fix a11y issues in style editor and user settings * Fix login a11y issues * eliminate a modal issue * Remove bad aria in rich text * Fix wrong aria in layout * changelog * Fix totp a11y issues, doc context state safety * Fix uncaught error - popup blockers/tests * Fix initial focus trap issue, introduced with recent changes (#5426) * PRO-9542: fix the bug that breaks sitemaps for RA (#5433) * PRO-9542: fix the bug that breaks sitemaps for RA * see changeset * Feature/prevent infinite redirects (#5429) * log aposResponse errors * add changeset * prevent infinite redirects to external URLs --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> * add draggable: false support to non-inline array field (#5435) * add draggable: false support to non-inline array field * Add changeset * Make logged-in cookie name configurable via options (#5430) The logged-in cookie name was hardcoded as 'loggedIn' with TODO comments indicating it should be configurable. This is needed for deployments where multiple Apostrophe instances share a domain (e.g., staging and production on subpaths) and need distinct cookie names to avoid conflicts. Changes: - Added 'loggedInCookieName' option to the login module (defaults to 'loggedIn' for backward compatibility) - Replaced all hardcoded references with self.loggedInCookieName - Removed the TODO comments Usage: modules: { '@apostrophecms/login': { options: { loggedInCookieName: 'myAppLoggedIn' } } } Addresses the TODO comments: 'get cookie name from config' Co-authored-by: Vangalla, Rohith <rohith.vangalla@optum.com> * Revert "Make logged-in cookie name configurable via options (#5430)" (#5436) This reverts commit ddcdaa7ff6864cd55d6fef9dfdfca2eaf63a5969. * Feature create-apostrophe (#5425) * Fix new schema areas in existing documents (Astro) (#5434) * Fix orphan or new-in-the-schema areas in external front-ends * Save missing empty areas in the DB, refactor nunjucks path * PRO-6295: jsx as an optional alternative to nunjucks (#5391) * jsx as an optional alternative to nunjucks * eslint, all tests pass * log a useful stack trace on attachment errors! Holy shit! * fix lint * clarify behavior * more tests pass linter * This is just a unit test, but it can't hurt to be thorough & satisfy github-advanced-security Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * true access to the apos object in jsx, per the spec * more test coverage, no code changes * fix watchers --------- Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * no watch in prod (#5439) * Fix new schema areas in existing documents (Astro) Part II (#5440) * Prevent data corruption when stubbing areas for Astro * Fix false positive orphan area warnings * Guard against corrupt area items * Fix raw-text sanitization bypass vulnerability and add regression tests (#5432) * changeset for singh contribution (#5442) * Fix relationship select scrolling issue (#5445) * Fix relationship select scrolling issue * Prevent same scrolling bugs to appear in media manager * jsx changeset (#5446) * Ensure install of the project root for astro projects (#5449) * test node 26 (#5450) * test node 26 * support node 26 by bumping the better-sqlite3 version * node 22 requirement * Add link for telemetry policy (#5455) * remove absent options (#5456) * Remove consumed 4.30.0 changesets from main (#5454) * cli links that are correct, or will be post publish (#5458) * release db connect to solve chicken and egg problem in cypress-tools (#5459) * Corrects documentation links (#5457) * Corrects documentation links * correct `guides` -> `guide` * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Security: added a number of new attributes to be protected against unsafe URLs, e.g. javascript: and similar. None of these are used in the default configuration of sanitize-html or apostrophe or likely to be used there, and some attributes, like an action for a form, are inherently unsafe to allow if XSS protection is your goal. Nevertheless it makes sense to block certain URL types where they are not appropriate. Thanks to [crattack](https://github.com/crattack) for reporting the vulnerability. * changeset * removed duplicate changeset * patch the right module * Mergeback latest (#5468) * Latest merge prerelease 2026 05 (#5404) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> (cherry picked from commit 9f458b5d9544d33239a0971b0050fff8bffe028a) * Bump CLI dependencies (#5383) (cherry picked from commit a5e1a4a35d01e09cbfd2c503370c95a8c2490867) * Native browser shortcuts work again (#5384) (cherry picked from commit b9b32bdd446add927c75d85e44d0a26814ba62b0) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments (cherry picked from commit 08845c5f23d95ead552ab9743a878daf997793a1) * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> (cherry picked from commit d45e27f6d66cd25fde0cf9c7199ee9d014fa1518) * merge back the thanks (#5388) (cherry picked from commit f3501f4de0448d4d0f8a01a1db4dc2fcf52c6218) * ignore inline table array as draggable ui for windows (#5392) (cherry picked from commit b360b05e8d4e479a36fcae45a5a6dbf820b8fba3) * Layout focus orchestration (#5393) (cherry picked from commit 77a2968206b0208883ff45de37feb43ba0b5d5b1) * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures (cherry picked from commit 008417fa9814dba4899b53b9394778dbd46ccf3c) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed (cherry picked from commit e9b3bac692315414da47fe05202e8854dd31d7ee) * Layout editable gap (#5397) (cherry picked from commit bc8f7bed381d4462a082976dd92b8d7f28180a95) * a11y fixes (#5401) (cherry picked from commit 2e2f3b4b46301fc81c46200f837e794b247a9aef) * clarifications (#5403) (cherry picked from commit 13f2c69f219a47f82972d8fa9036deddd84223dc) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Latest security merge (#5407) * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * Merge commit from fork * Merge commit from fork * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * release only (changelogs formatted) (#5408) * allow oembetter to be released (#5412) * release oembetter 1.2.0 (#5413) * release oembetter 1.2.0 * left commit * [latest[ PRO-9441: modal focus trap * [latest] Fix import-export noise * [latest] A11y fixes part 3 * Fix initial focus trap issue, introduced with recent changes (#5427) * merge main to latest (#5460) * Latest security q2 (#5463) * Bump CLI dependencies (#5383) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> * Native browser shortcuts work again (#5384) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> * merge back the thanks (#5388) * Postgres (#5365) * postgres experimental WIP * astonishingly, all mocha tests of apostrophe pass with this * mocha tests pass, actual sites work * lint clean * listDatabases support, but changes are coming * wip * dump and restore updates * backpressure, adequate handling of ObjectId for our needs (becomes its hex representation) * mild performance optimization * profiling * testing issue resolved * refactored to db-connect module, introduced sqlite adapter * sqlite WIP * debugging * programmatic API for dump/restore/copy dbs * linting, documentation * MIT license * text ranking is more accurate, documentation is more complete * good full text search for sqlite * updates for compatibility with the rest of the public and private modules, plus a few fixes to genuinely ambiguous tests * requirements found by testing private modules * fixes from full cypress run * eslint passing * restore permissions * maximize atomicity * bug fixes * * exit properly when asset tests fail * "npm test" tests all three adapters * ignore claude-tools in eslint * postgres and sqlite-inclusive ci matrix attempt * clean up logs * We hit github's limit on total configurations because every package gets its own matrix. Solve that with grouping: * apostrophe core * All regular ecosystem packages other than core * non-database-requiring packges * mongodb-specific packages This will probably speed it up too because it won't have to spin up a container a bazillion times. * hardened the asset tests, made them less timing sensitive, fixed a bad commit resulting from the way they dodgily patch themselves without a robust cleanup mechanism * fix a root cause of asset test instability * log mess * implemented missing $size operator * test compatibility * advanced permission uses regex in $in * regex in $in * .db() should not make false promises in plain postgres mode, it should fail * ability to specify a default adapter * obsolete file * put escapeHost back where it belongs * dead code removal, test cleanup * emulate-mongo-3-driver only needed in db-connect * no claude logs in repo (tools are welcome) * * shared aggregation implementation, other shared things * optimize $match when it is the first step in aggregation, don't fetch the whole collection 😜 * multipostgres listDatabases() and .db() should return and expect "fully qualified virtual database names," e.g. physical_db_name-schemaname * vanilla postgres should not attempt to use .db() with alternate names in tests * documentation corrections * documentation errors * listDatabases and documentation corrections * more edge cases revealed by latest work from Miro * anchored prefix regexps are optimized documentation improvements * * matchesQuery in the aggregation cursor implementation doesn't throw on unrecognized operators. It should, and it should support the same mongodb operators that the regular find() path does in postgres/sqlite (our official subset), unless there is an extraordinary reason not to. * Similarly, the main query implementation for normal queries should throw on unrecognized operators if it doesn't already. * The dump/restore programmatic APIs in db-connect concern me. These involve returning the entire database as a string, which could exhaust memory. This impacts both utilities and also copyDatabase(). Could these APIs return and expect async iterators instead of strings? * The test "anchored regex on an indexed field uses a btree index search" runs explain on a query that's hardcoded in the test. Instead these SQL based adapters should expose a means to get the SQL for a query, so it can be directly tested. Otherwise this test proves nothing as changes to the adapter accumulate in future. * Why is this test searching for "at least 1" and not exactly 1? it('should find documents with null value', async function() { const docs = await db.collection('test').find({ value: null }).toArray(); // MongoDB matches both null and missing fields with { value: null } expect(docs.length).to.be.at.least(1); }); * What is the maximum size of a db-connect document in the postgres and sqlite adapters? * Update the copyright year in db-connect/LICENSE.md to 2025. * The db-connect README mentions: sqlite://:memory: What happens if you try to use .db('some-name') with that? I think it would be best to just not support throwaway in-memory sqlite databases because I doubt anyone would intentionally store a website in one. * do not swallow dump/restore errors on indexes * cover how to run the utilities * fix detection of source * separate sanitization for index names * regex prefix safety * pnpm --------- Co-authored-by: Thomas Boutell <boutell@vcs.trox.local> * forgot to include a changeset (#5390) * ignore inline table array as draggable ui for windows (#5392) * Layout focus orchestration (#5393) * Pro 9405 remove hreflang (#5395) * Remove hreflang generation and update README * Add changeset * Changeset update * Pro 9406 base url (#5396) * Removes `seoSiteCanonicalUrl` * Update tests and remove missed log * Change semver level * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures * Pro 9405 remove hreflang (#5395) * Remove hreflang generation and update README * Add changeset * Changeset update * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed * Layout editable gap (#5397) * a11y fixes (#5401) * clarifications (#5403) * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * Merge commit from fork * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * mergeback (#5409) * Latest merge prerelease 2026 05 (#5404) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> (cherry picked from commit 9f458b5d9544d33239a0971b0050fff8bffe028a) * Bump CLI dependencies (#5383) (cherry picked from commit a5e1a4a35d01e09cbfd2c503370c95a8c2490867) * Native browser shortcuts work again (#5384) (cherry picked from commit b9b32bdd446add927c75d85e44d0a26814ba62b0) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments (cherry picked from commit 08845c5f23d95ead552ab9743a878daf997793a1) * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> (cherry picked from commit d45e27f6d66cd25fde0cf9c7199ee9d014fa1518) * merge back the thanks (#5388) (cherry picked from commit f3501f4de0448d4d0f8a01a1db4dc2fcf52c6218) * ignore inline table array as draggable ui for windows (#5392) (cherry picked from commit b360b05e8d4e479a36fcae45a5a6dbf820b8fba3) * Layout focus orchestration (#5393) (cherry picked from commit 77a2968206b0208883ff45de37feb43ba0b5d5b1) * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures (cherry picked from commit 008417fa9814dba4899b53b9394778dbd46ccf3c) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed (cherry picked from commit e9b3bac692315414da47fe05202e8854dd31d7ee) * Layout editable gap (#5397) (cherry picked from commit bc8f7bed381d4462a082976dd92b8d7f28180a95) * a11y fixes (#5401) (cherry picked from commit 2e2f3b4b46301fc81c46200f837e794b247a9aef) * clarifications (#5403) (cherry picked from commit 13f2c69f219a47f82972d8fa9036deddd84223dc) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Latest security merge (#5407) * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * Merge commit from fork * Merge commit from fork * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * release only (changelogs formatted) (#5408) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * mergeback (#5414) * Latest merge prerelease 2026 05 (#5404) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> (cherry picked from commit 9f458b5d9544d33239a0971b0050fff8bffe028a) * Bump CLI dependencies (#5383) (cherry picked from commit a5e1a4a35d01e09cbfd2c503370c95a8c2490867) * Native browser shortcuts work again (#5384) (cherry picked from commit b9b32bdd446add927c75d85e44d0a26814ba62b0) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments (cherry picked from commit 08845c5f23d95ead552ab9743a878daf997793a1) * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> (cherry picked from commit d45e27f6d66cd25fde0cf9c7199ee9d014fa1518) * merge back the thanks (#5388) (cherry picked from commit f3501f4de0448d4d0f8a01a1db4dc2fcf52c6218) * ignore inline table array as draggable ui for windows (#5392) (cherry picked from commit b360b05e8d4e479a36fcae45a5a6dbf820b8fba3) * Layout focus orchestration (#5393) (cherry picked from commit 77a2968206b0208883ff45de37feb43ba0b5d5b1) * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures (cherry picked from commit 008417fa9814dba4899b53b9394778dbd46ccf3c) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed (cherry picked from commit e9b3bac692315414da47fe05202e8854dd31d7ee) * Layout editable gap (#5397) (cherry picked from commit bc8f7bed381d4462a082976dd92b8d7f28180a95) * a11y fixes (#5401) (cherry picked from commit 2e2f3b4b46301fc81c46200f837e794b247a9aef) * clarifications (#5403) (cherry picked from commit 13f2c69f219a47f82972d8fa9036deddd84223dc) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Latest security merge (#5407) * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * Merge commit from fork * Merge commit from fork * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * release only (changelogs formatted) (#5408) * allow oembetter to be released (#5412) * release oembetter 1.2.0 (#5413) * release oembetter 1.2.0 * left commit --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Fix focus trap on the last element in a modal (#5406) * Fix focus trap on the last element in a modal * Fix trap escaping edge cases * Fix import-export noise (#5399) * remove noise, switch to utils debug * Fix tests * Introduce debug option * changelog * Fix test sorting issue * A11y fixes part 3 (#5416) * Fix editor modal a11y issues * Fix manager a11y problems * Fix page manager a11y problems * fix media manager a11y issues * fix a11y issues in style editor and user settings * Fix login a11y issues * eliminate a modal issue * Remove bad aria in rich text * Fix wrong aria in layout * changelog * Fix totp a11y issues, doc context state safety * Fix uncaught error - popup blockers/tests * Fix initial focus trap issue, introduced with recent changes (#5426) * PRO-9542: fix the bug that breaks sitemaps for RA (#5433) * PRO-9542: fix the bug that breaks sitemaps for RA * see changeset * Feature/prevent infinite redirects (#5429) * log aposResponse errors * add changeset * prevent infinite redirects to external URLs --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> * add draggable: false support to non-inline array field (#5435) * add draggable: false support to non-inline array field * Add changeset * Make logged-in cookie name configurable via options (#5430) The logged-in cookie name was hardcoded as 'loggedIn' with TODO comments indicating it should be configurable. This is needed for deployments where multiple Apostrophe instances share a domain (e.g., staging and production on subpaths) and need distinct cookie names to avoid conflicts. Changes: - Added 'loggedInCookieName' option to the login module (defaults to 'loggedIn' for backward compatibility) - Replaced all hardcoded references with self.loggedInCookieName - Removed the TODO comments Usage: modules: { '@apostrophecms/login': { options: { loggedInCookieName: 'myAppLoggedIn' } } } Addresses the TODO comments: 'get cookie name from config' Co-authored-by: Vangalla, Rohith <rohith.vangalla@optum.com> * Revert "Make logged-in cookie name configurable via options (#5430)" (#5436) This reverts commit ddcdaa7ff6864cd55d6fef9dfdfca2eaf63a5969. * Feature create-apostrophe (#5425) * Fix new schema areas in existing documents (Astro) (#5434) * Fix orphan or new-in-the-schema areas in external front-ends * Save missing empty areas in the DB, refactor nunjucks path * PRO-6295: jsx as an optional alternative to nunjucks (#5391) * jsx as an optional alternative to nunjucks * eslint, all tests pass * log a useful stack trace on attachment errors! Holy shit! * fix lint * clarify behavior * more tests pass linter * This is just a unit test, but it can't hurt to be thorough & satisfy github-advanced-security Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * true access to the apos object in jsx, per the spec * more test coverage, no code changes * fix watchers --------- Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * no watch in prod (#5439) * Fix new schema areas in existing documents (Astro) Part II (#5440) * Prevent data corruption when stubbing areas for Astro * Fix false positive orphan area warnings * Guard against corrupt area items * Fix raw-text sanitization bypass vulnerability and add regression tests (#5432) * changeset for singh contribution (#5442) * Fix relationship select scrolling issue (#5445) * Fix relationship select scrolling issue * Prevent same scrolling bugs to appear in media manager * jsx changeset (#5446) * Ensure install of the project root for astro projects (#5449) * test node 26 (#5450) * test node 26 * support node 26 by bumping the better-sqlite3 version * node 22 requirement * Add link for telemetry policy (#5455) * remove absent options (#5456) * Remove consumed 4.30.0 changesets from main (#5454) * cli links that are correct, or will be post publish (#5458) * release db connect to solve chicken and egg problem in cypress-tools (#5459) * Corrects documentation links (#5457) * Corrects documentation links * correct `guides` -> `guide` --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Thomas Boutell <boutell@vcs.trox.local> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> Co-authored-by: RohithVangalla1 <reachrohithv@gmail.com> Co-authored-by: Vangalla, Rohith <rohith.vangalla@optum.com> Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> Co-authored-by: Dipanshu singh <161134993+Dipanshusinghh@users.noreply.github.com> * Latest security q2 (#5464) * Bump CLI dependencies (#5383) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> * Native browser shortcuts work again (#5384) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> * merge back the thanks (#5388) * Postgres (#5365) * postgres experimental WIP * astonishingly, all mocha tests of apostrophe pass with this * mocha tests pass, actual sites work * lint clean * listDatabases support, but changes are coming * wip * dump and restore updates * backpressure, adequate handling of ObjectId for our needs (becomes its hex representation) * mild performance optimization * profiling * testing issue resolved * refactored to db-connect module, introduced sqlite adapter * sqlite WIP * debugging * programmatic API for dump/restore/copy dbs * linting, documentation * MIT license * text ranking is more accurate, documentation is more complete * good full text search for sqlite * updates for compatibility with the rest of the public and private modules, plus a few fixes to genuinely ambiguous tests * requirements found by testing private modules * fixes from full cypress run * eslint passing * restore permissions * maximize atomicity * bug fixes * * exit properly when asset tests fail * "npm test" tests all three adapters * ignore claude-tools in eslint * postgres and sqlite-inclusive ci matrix attempt * clean up logs * We hit github's limit on total configurations because every package gets its own matrix. Solve that with grouping: * apostrophe core * All regular ecosystem packages other than core * non-database-requiring packges * mongodb-specific packages This will probably speed it up too because it won't have to spin up a container a bazillion times. * hardened the asset tests, made them less timing sensitive, fixed a bad commit resulting from the way they dodgily patch themselves without a robust cleanup mechanism * fix a root cause of asset test instability * log mess * implemented missing $size operator * test compatibility * advanced permission uses regex in $in * regex in $in * .db() should not make false promises in plain postgres mode, it should fail * ability to specify a default adapter * obsolete file * put escapeHost back where it belongs * dead code removal, test cleanup * emulate-mongo-3-driver only needed in db-connect * no claude logs in repo (tools are welcome) * * shared aggregation implementation, other shared things * optimize $match when it is the first step in aggregation, don't fetch the whole collection 😜 * multipostgres listDatabases() and .db() should return and expect "fully qualified virtual database names," e.g. physical_db_name-schemaname * vanilla postgres should not attempt to use .db() with alternate names in tests * documentation corrections * documentation errors * listDatabases and documentation corrections * more edge cases revealed by latest work from Miro * anchored prefix regexps are optimized documentation improvements * * matchesQuery in the aggregation cursor implementation doesn't throw on unrecognized operators. It should, and it should support the same mongodb operators that the regular find() path does in postgres/sqlite (our official subset), unless there is an extraordinary reason not to. * Similarly, the main query implementation for normal queries should throw on unrecognized operators if it doesn't already. * The dump/restore programmatic APIs in db-connect concern me. These involve returning the entire database as a string, which could exhaust memory. This impacts both utilities and also copyDatabase(). Could these APIs return and expect async iterators instead of strings? * The test "anchored regex on an indexed field uses a btree index search" runs explain on a query that's hardcoded in the test. Instead these SQL based adapters should expose a means to get the SQL for a query, so it can be directly tested. Otherwise this test proves nothing as changes to the adapter accumulate in future. * Why is this test searching for "at least 1" and not exactly 1? it('should find documents with null value', async function() { const docs = await db.collection('test').find({ value: null }).toArray(); // MongoDB matches both null and missing fields with { value: null } expect(docs.length).to.be.at.least(1); }); * What is the maximum size of a db-connect document in the postgres and sqlite adapters? * Update the copyright year in db-connect/LICENSE.md to 2025. * The db-connect README mentions: sqlite://:memory: What happens if you try to use .db('some-name') with that? I think it would be best to just not support throwaway in-memory sqlite databases because I doubt anyone would intentionally store a website in one. * do not swallow dump/restore errors on indexes * cover how to run the utilities * fix detection of source * separate sanitization for index names * regex prefix safety * pnpm --------- Co-authored-by: Thomas Boutell <boutell@vcs.trox.local> * forgot to include a changeset (#5390) * ignore inline table array as draggable ui for windows (#5392) * Layout focus orchestration (#5393) * Pro 9405 remove hreflang (#5395) * Remove hreflang generation and update README * Add changeset * Changeset update * Pro 9406 base url (#5396) * Removes `seoSiteCanonicalUrl` * Update tests and remove missed log * Change semver level * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures * Pro 9405 remove hreflang (#5395) * Remove hreflang generation and update README * Add changeset * Changeset update * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed * Layout editable gap (#5397) * a11y fixes (#5401) * clarifications (#5403) * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * Merge commit from fork * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * mergeback (#5409) * Latest merge prerelease 2026 05 (#5404) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> (cherry picked from commit 9f458b5d9544d33239a0971b0050fff8bffe028a) * Bump CLI dependencies (#5383) (cherry picked from commit a5e1a4a35d01e09cbfd2c503370c95a8c2490867) * Native browser shortcuts work again (#5384) (cherry picked from commit b9b32bdd446add927c75d85e44d0a26814ba62b0) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments (cherry picked from commit 08845c5f23d95ead552ab9743a878daf997793a1) * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> (cherry picked from commit d45e27f6d66cd25fde0cf9c7199ee9d014fa1518) * merge back the thanks (#5388) (cherry picked from commit f3501f4de0448d4d0f8a01a1db4dc2fcf52c6218) * ignore inline table array as draggable ui for windows (#5392) (cherry picked from commit b360b05e8d4e479a36fcae45a5a6dbf820b8fba3) * Layout focus orchestration (#5393) (cherry picked from commit 77a2968206b0208883ff45de37feb43ba0b5d5b1) * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures (cherry picked from commit 008417fa9814dba4899b53b9394778dbd46ccf3c) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed (cherry picked from commit e9b3bac692315414da47fe05202e8854dd31d7ee) * Layout editable gap (#5397) (cherry picked from commit bc8f7bed381d4462a082976dd92b8d7f28180a95) * a11y fixes (#5401) (cherry picked from commit 2e2f3b4b46301fc81c46200f837e794b247a9aef) * clarifications (#5403) (cherry picked from commit 13f2c69f219a47f82972d8fa9036deddd84223dc) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Latest security merge (#5407) * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * Merge commit from fork * Merge commit from fork * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * release only (changelogs formatted) (#5408) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * mergeback (#5414) * Latest merge prerelease 2026 05 (#5404) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> (cherry picked from commit 9f458b5d9544d33239a0971b0050fff8bffe028a) * Bump CLI dependencies (#5383) (cherry picked from commit a5e1a4a35d01e09cbfd2c503370c95a8c2490867) * Native browser shortcuts work again (#5384) (cherry picked from commit b9b32bdd446add927c75d85e44d0a26814ba62b0) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments (cherry picked from commit 08845c5f23d95ead552ab9743a878daf997793a1) * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> (cherry picked from commit d45e27f6d66cd25fde0cf9c7199ee9d014fa1518) * merge back the thanks (#5388) (cherry picked from commit f3501f4de0448d4d0f8a01a1db4dc2fcf52c6218) * ignore inline table array as draggable ui for windows (#5392) (cherry picked from commit b360b05e8d4e479a36fcae45a5a6dbf820b8fba3) * Layout focus orchestration (#5393) (cherry picked from commit 77a2968206b0208883ff45de37feb43ba0b5d5b1) * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures (cherry picked from commit 008417fa9814dba4899b53b9394778dbd46ccf3c) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed (cherry picked from commit e9b3bac692315414da47fe05202e8854dd31d7ee) * Layout editable gap (#5397) (cherry picked from commit bc8f7bed381d4462a082976dd92b8d7f28180a95) * a11y fixes (#5401) (cherry picked from commit 2e2f3b4b46301fc81c46200f837e794b247a9aef) * clarifications (#5403) (cherry picked from commit 13f2c69f219a47f82972d8fa9036deddd84223dc) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Latest security merge (#5407) * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * Merge commit from fork * Merge commit from fork * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * release only (changelogs formatted) (#5408) * allow oembetter to be released (#5412) * release oembetter 1.2.0 (#5413) * release oembetter 1.2.0 * left commit --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Fix focus trap on the last element in a modal (#5406) * Fix focus trap on the last element in a modal * Fix trap escaping edge cases * Fix import-export noise (#5399) * remove noise, switch to utils debug * Fix tests * Introduce debug option * changelog * Fix test sorting issue * A11y fixes part 3 (#5416) * Fix editor modal a11y issues * Fix manager a11y problems * Fix page manager a11y problems * fix media manager a11y issues * fix a11y issues in style editor and user settings * Fix login a11y issues * eliminate a modal issue * Remove bad aria in rich text * Fix wrong aria in layout * changelog * Fix totp a11y issues, doc context state safety * Fix uncaught error - popup blockers/tests * Fix initial focus trap issue, introduced with recent changes (#5426) * PRO-9542: fix the bug that breaks sitemaps for RA (#5433) * PRO-9542: fix the bug that breaks sitemaps for RA * see changeset * Feature/prevent infinite redirects (#5429) * log aposResponse errors * add changeset * prevent infinite redirects to external URLs --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> * add draggable: false support to non-inline array field (#5435) * add draggable: false support to non-inline array field * Add changeset * Make logged-in cookie name configurable via options (#5430) The logged-in cookie name was hardcoded as 'loggedIn' with TODO comments indicating it should be configurable. This is needed for deployments where multiple Apostrophe instances share a domain (e.g., staging and production on subpaths) and need distinct cookie names to avoid conflicts. Changes: - Added 'loggedInCookieName' option to the login module (defaults to 'loggedIn' for backward compatibility) - Replaced all hardcoded references with self.loggedInCookieName - Removed the TODO comments Usage: modules: { '@apostrophecms/login': { options: { loggedInCookieName: 'myAppLoggedIn' } } } Addresses the TODO comments: 'get cookie name from config' Co-authored-by: Vangalla, Rohith <rohith.vangalla@optum.com> * Revert "Make logged-in cookie name configurable via options (#5430)" (#5436) This reverts commit ddcdaa7ff6864cd55d6fef9dfdfca2eaf63a5969. * Feature create-apostrophe (#5425) * Fix new schema areas in existing documents (Astro) (#5434) * Fix orphan or new-in-the-schema areas in external front-ends * Save missing empty areas in the DB, refactor nunjucks path * PRO-6295: jsx as an optional alternative to nunjucks (#5391) * jsx as an optional alternative to nunjucks * eslint, all tests pass * log a useful stack trace on attachment errors! Holy shit! * fix lint * clarify behavior * more tests pass linter * This is just a unit test, but it can't hurt to be thorough & satisfy github-advanced-security Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * true access to the apos object in jsx, per the spec * more test coverage, no code changes * fix watchers --------- Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * no watch in prod (#5439) * Fix new schema areas in existing documents (Astro) Part II (#5440) * Prevent data corruption when stubbing areas for Astro * Fix false positive orphan area warnings * Guard against corrupt area items * Fix raw-text sanitization bypass vulnerability and add regression tests (#5432) * changeset for singh contribution (#5442) * Fix relationship select scrolling issue (#5445) * Fix relationship select scrolling issue * Prevent same scrolling bugs to appear in media manager * jsx changeset (#5446) * Ensure install of the project root for astro projects (#5449) * test node 26 (#5450) * test node 26 * support node 26 by bumping the better-sqlite3 version * node 22 requirement * Add link for telemetry policy (#5455) * remove absent options (#5456) * Remove consumed 4.30.0 changesets from main (#5454) * cli links that are correct, or will be post publish (#5458) * release db connect to solve chicken and egg problem in cypress-tools (#5459) * Corrects documentation links (#5457) * Corrects documentation links * correct `guides` -> `guide` * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Security: added a number of new attributes to be protected against unsafe URLs, e.g. javascript: and similar. None of these are used in the default configuration of sanitize-html or apostrophe or likely to be used there, and some attributes, like an action for a form, are inherently unsafe to allow if XSS protection is your goal. Nevertheless it makes sense to block certain URL types where they are not appropriate. Thanks to [crattack](https://github.com/crattack) for reporting the vulnerability. * changeset * removed duplicate changeset * patch the right module --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Thomas Boutell <boutell@vcs.trox.local> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> Co-authored-by: RohithVangalla1 <reachrohithv@gmail.com> Co-authored-by: Vangalla, Rohith <rohith.vangalla@optum.com> Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> Co-authored-by: Dipanshu singh <161134993+Dipanshusinghh@users.noreply.github.com> * release and changelog edits (#5465) * changelogs * formatting --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> Co-authored-by: Thomas Boutell <boutell@vcs.trox.local> Co-authored-by: RohithVangalla1 <reachrohithv@gmail.com> Co-authored-by: Vangalla, Rohith <rohith.vangalla@optum.com> Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> Co-authored-by: Dipanshu singh <161134993+Dipanshusinghh@users.noreply.github.com> * Hotfix cli links (#5469) * Fix broken link * Add changeset * Hotfix cli links (#5469) * Fix broken link * Add changeset * Fix asset URLs when a site prefix is configured (#5448) * Mergeup latest to main (#5473) * Latest merge prerelease 2026 05 (#5404) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> (cherry picked from commit 9f458b5d9544d33239a0971b0050fff8bffe028a) * Bump CLI dependencies (#5383) (cherry picked from commit a5e1a4a35d01e09cbfd2c503370c95a8c2490867) * Native browser shortcuts work again (#5384) (cherry picked from commit b9b32bdd446add927c75d85e44d0a26814ba62b0) * Pro 8838 charset (#5385) * Removes encoding option …
1 parent 0b98f7b commit 207846a

29 files changed

Lines changed: 206 additions & 42 deletions

File tree

‎packages/apostrophe-astro/CHANGELOG.md‎

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,33 @@
11
# Changelog
22

3+
## 1.14.0 (2026-07-10)
4+
5+
### Adds
6+
7+
- In SSR mode, the integration now automatically serves _literal content_ files declared by Apostrophe modules - such as `robots.txt`, `sitemap.xml`, and `llms.txt` - by proxying them directly to Apostrophe instead of rendering them as pages. These files no longer need to be listed individually in the `proxyRoutes` option, which continues to work as before for any additional routes you wish to proxy.
8+
9+
### Changes
10+
11+
- Upgraded the `undici` HTTP client from v6 to v8, which requires Node.js 22.19 or newer, and fixed a connection leak in the Astro proxy where responses that are not streamed on to the browser — redirects (301/302/307/308) and bodyless responses (204/304) — now release their backend response body immediately instead of leaving it for garbage collection, which under load could hold connections open and exhaust the connection pool.
12+
- Replace vite-plugin-apostrophe-config and vite-plugin-apostrophe-doctype with vite/vite-plugin-apostrophe-generated-config.js, which writes real files to node_modules/.apostrophe-astro-config/ (config.js, doctypes.js)
13+
14+
- Register Vite aliases for apostrophe-astro-config/config and /doctypes
15+
- Update all internal virtual: imports to alias specifiers
16+
- Rename static build cache dir to node_modules/.apostrophe-astro-static/
17+
- Add helpers/server/ (aposFetch, getAposHost, isStaticBuild)
18+
- Add helpers/universal/ (URL, slug, styles, attachment helpers)
19+
- Keep lib/aposPageFetch.js as the internal implementation (starter kit entrypoint only)
20+
- Reduce lib/util.js, lib/aposSetQueryParameter.js, lib/static.js to deprecated shims
21+
- Add MIGRATION.md
22+
- Bump `undici` to ^7.x for Node.js 24+ compatibility
23+
- Add `peerDependencies` declaring Astro v5, v6, and v7 support.
24+
- Fix `virtual:apostrophe-config` import in `aposLiteralContentMiddleware.js` to use the generated-file module path.
25+
- Drop deprecated entryPoint shim from injectRoute calls.
26+
27+
### Fixes
28+
29+
- Query string parameters are no longer lost when a URL with a trailing slash is normalized, so `/articles/?page=2` now renders the same content as `/articles?page=2`. Previously such URLs were redirected to the page URL alone (e.g. `/articles`), losing the query string and showing the first page. Redirects to a different origin are now always passed through to the browser.
30+
331
## 1.13.0 (2026-06-10)
432

533
### Fixes

‎packages/apostrophe-astro/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "@apostrophecms/apostrophe-astro",
3-
"version": "1.13.0",
3+
"version": "1.14.0",
44
"type": "module",
55
"description": "Apostrophe integration for Astro",
66
"repository": {

‎packages/apostrophe/CHANGELOG.md‎

Lines changed: 48 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,52 @@
11
# Changelog
22

3+
## 4.32.0 (2026-07-10)
4+
5+
### Adds
6+
7+
- Added support for modules to declare _literal content_ routes - URLs that serve non-page files such as `robots.txt`, `sitemap.xml`, or `llms.txt` rather than rendered pages. External front-end integrations (such as the Astro integration) can now read these routes and serve such files correctly instead of attempting to render them as pages. Custom modules can contribute their own routes by handling the new `@apostrophecms/url:getLiteralContentRoutes` event.
8+
9+
### Changes
10+
11+
- The server-side HTTP client (`apos.http`) now uses Node's built-in `fetch` instead of `node-fetch`.
12+
13+
`node-fetch` is no longer maintained, and Node's built-in `fetch` is its standard, actively maintained successor, available in every Node.js version Apostrophe supports - so this is the right time to adopt it. We do not consider this a breaking change: common `apos.http.*` usage is unchanged, and we deliberately preserved compatibility where it mattered - `form-data` request bodies, cookie jars, the `timeout` option (now backed by an `AbortSignal`), and absolute redirect `Location` headers all behave as before.
14+
15+
Most code that calls `apos.http.get()`, `apos.http.post()`, etc. needs no changes. A few things to be aware of if you use advanced options or read raw responses:
16+
17+
- The `agent` option is no longer supported (the built-in `fetch` has no equivalent). Pass an undici `dispatcher` instead; `apos.http` throws if `agent` is given.
18+
- A `Host` request header can no longer be set (it is disallowed by the fetch standard and is silently ignored).
19+
- `originalResponse: true` now resolves with the built-in `fetch` `Response`. Its `body` is a web `ReadableStream` (use `require('node:stream').Readable.fromWeb()` to read it as a Node stream), and node-fetch-only helpers such as `.buffer()` are no longer available.
20+
- Requests that send a conditional header (`If-None-Match` / `If-Modified-Since`) now also send `Cache-Control: no-cache`, as required by the fetch standard. An endpoint that returns `304 Not Modified` based on those headers may return `200` to such a request.
21+
22+
New capabilities:
23+
24+
- The `timeout` option (in milliseconds) and the standard `signal` (`AbortSignal`) and undici `dispatcher` options are supported.
25+
- A request `body` may be a native `FormData`, in addition to a `form-data` package instance.
26+
27+
- Bumped `glob` to `^13` (core) and `rimraf` to `^6` (uploadfs) to clear the deprecated `glob@10` warning shown on every install. The old `glob@10` arrived both directly from core and transitively through `uploadfs` → `rimraf@5`; both now resolve to the current, supported `glob@13` (`rimraf@6` depends on `glob@13` as well). No API or behavior changes.
28+
29+
### Fixes
30+
31+
- Fixed the tag popover in the media library (used to apply tags to images in bulk) so it loads all image tags instead of only the first 50. Tags beyond the first 50 can now be found and applied, and creating a tag whose name already exists no longer produces a duplicate.
32+
- The lock file dependency check that forces a full rebuild now runs once per process. Watcher-triggered rebuilds stay scoped to the detected changes instead of rebuilding everything on every file change when the lock file changed or is absent. This bug was in effect only for projects missing a lock file in their `npmRoot` (e.g. npm monorepos).
33+
- Fixed the admin UI sometimes serving a stale build after dependencies changed (for example after `npm install` or `npm update`). Apostrophe now detects dependency changes from the content of the lock file rather than its modified time, which could be misleading after a fresh checkout or a restored CI/Docker build cache.
34+
35+
For external build module authors: lock file change detection now happens in the core and is passed to the build module via the `lockChanged` build option. The `apos.asset.getSystemLastChangeMs()` helper is deprecated and the build manifest no longer includes a `ts` timestamp.
36+
37+
- Fixed pressing Backspace right after typing `/` in a rich text widget deleting the entire widget. Backspace now removes the slash and closes the insert menu. Global command menu shortcuts also no longer fire for key events already handled and prevented by other UI components.
38+
- Fix invalid HTML output for <col> elements in sanitize-html (treat void elements correctly)
39+
- Fixed a layout issue where `dateAndTime` schema fields could overflow and trigger horizontal scrolling in narrow containers.
40+
- fromRichText adds metatype to new widget
41+
- Fixed the widget copy shortcut (Ctrl+C / Cmd+C) hijacking native text copy in edit mode. With an active text selection, the cut, copy and remove (Backspace) widget shortcuts now defer to the browser. Pasting a widget with Ctrl+V / Cmd+V now checks that the widget copy is still the most recent thing in the system clipboard, so text copied elsewhere in the meantime is no longer shadowed by a stale widget paste. The widget clipboard storage remains backward compatible with entries written by previous releases.
42+
- Batch jobs now reliably record their total item count, so completion notifications no longer occasionally report a null total.
43+
44+
### Security
45+
46+
- Completed the fix for CVE-2026-39857 (GHSA-xmpp-f9v3-r7qh). The `.choices()` / `.counts()` query builders (`?choices=` / `?counts=` on the public REST API) guarded against leaking distinct values of fields excluded from `publicApiProjection` by resolving the schema field with an exact-name match. A relationship field registers extra query builders whose names differ from the field name — the "slug" alias builders that drop the leading underscore (`author` / `authorAnd` for a field named `_author`) and the `_authorAnd` operation builder — so those aliases were not gated and could still be used by an unauthenticated caller to extract the relationship's distinct choices (the referenced, publicly visible related documents by title/slug, plus per-value counts via `?counts=`) for a relationship an operator intentionally excluded from `publicApiProjection`. Relationship alias builders are now resolved back to their underlying schema field (matching the field name or its `idsStorage`) before the `publicApiProjection` and `viewPermission` checks are applied, so the alias names are gated exactly like the field itself. Thanks to Ta Duc Thien ([thientd](https://github.com/thientd)) for reporting this issue.
47+
- Restored destination-parent authorization in the page `move()` operation (GHSA-wr5r-wqp2-x4fh). A regression had gated the destination "create" permission check on the source page being restored out of the archive, which silently disabled that check for every ordinary move. As a result a low-privileged but content-editing user (for example an editor) who could edit at least one page could relocate that page under a parent of a restricted page type they have no create/edit rights over (such as one declaring a higher `editRole`/`publishRole`), and in doing so trigger an unchecked re-ranking of the restricted parent's existing children. A cross-parent move into a non-archive destination now again requires "create" permission on the destination, with the archive-restore path handled as an explicit exception. Thanks to 5ud0 / Tarmo Technologies for reporting the issue.
48+
- Bumped the `nodemailer` dependency from 8.x to 9.x to pick up the fix for GHSA-p6gq-j5cr-w38f, where a message's `raw` option could bypass nodemailer's `disableFileAccess`/`disableUrlAccess` controls and enable arbitrary file reads or SSRF. The real-world risk to Apostrophe is low: core only sends mail from trusted server-side code (such as password-reset emails), never sets those controls, and gives site visitors no way to control a message's `raw` field. nodemailer 9 is a security-only major release with one behavior change worth noting for projects: outbound HTTPS used to fetch remote content (remote-URL attachments, OAuth2 token endpoints, HTTP/HTTPS proxies) now validates TLS certificates by default — if you depend on self-signed or otherwise invalid certificates, opt out per request with `tls.rejectUnauthorized: false`. As a precaution, make sure your own project code never forwards untrusted input into the `raw` field of a module's `email()` call.
49+
350
## 4.31.0 (2026-06-10)
451

552
### Adds
@@ -12,7 +59,7 @@
1259
### Fixes
1360

1461
- Fixed an issue where using the Tab key to navigate within modals could incorrectly jump focus to a wrong element instead of the next input field.
15-
Fixed Tab navigation escaping out of modals when the form contained hidden sections or elements that became disabled after editing.
62+
Fixed Tab navigation escaping out of modals when the form contained hidden sections or elements that became disabled after editing.
1663
- Fixed adding or removing an area field from a schema breaking existing documents on an external front such as Astro.
1764
- For Astro: `AposArea` now renders only schema-backed areas. A missing area no longer throws, and an area orphaned by removing its field from the schema (while its content remains in the document) renders nothing instead of breaking sibling areas in edit mode. Logged-in editors get a diagnostic message in place of an orphaned area; anonymous visitors see nothing.
1865
- Editable documents sent to an external front (Asgtro) now materialize empty area objects for schema area fields added after the document was created, so they can be edited in context.

‎packages/apostrophe/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "apostrophe",
3-
"version": "4.31.0",
3+
"version": "4.32.0",
44
"description": "The Apostrophe Content Management System.",
55
"main": "index.js",
66
"scripts": {

‎packages/create-apostrophe/CHANGELOG.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,11 @@
11
# create-apostrophe
22

3+
## 1.1.0 (2026-07-10)
4+
5+
### Fixes
6+
7+
- Fixed `npm create apostrophe` with the SQLite database option under npm v12 (and when run from a global `@apostrophecms/cli` install). The installer now performs its post-install database work using the newly generated project's own `better-sqlite3`, rather than the installer's bundled copy.
8+
39
## 1.0.1 (2026-06-10)
410

511
### Fixes

‎packages/create-apostrophe/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "create-apostrophe",
3-
"version": "1.0.1",
3+
"version": "1.1.0",
44
"description": "Guided installer for ApostropheCMS — npm create apostrophe@latest",
55
"type": "module",
66
"engines": {

‎packages/emulate-mongo-3-driver/CHANGELOG.md‎

Lines changed: 14 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,45 +1,51 @@
11
# CHANGELOG
22

3+
## 1.0.7 (2026-07-10)
4+
5+
### Fixes
6+
7+
- Patching the `mongodb-legacy` classes is now idempotent. When two copies of this package are loaded against the same `mongodb-legacy` instance (for example, a version or source skew between a direct and a transitive dependency), the second copy no longer throws `TypeError: Cannot redefine property: Symbol(@@mdb.callbacks.toEmulate)`. The emulation method is defined only once and is now `configurable`, so any mix of patched and unpatched copies can load in either order without error.
8+
39
## 1.0.6 (2024-07-19)
410

511
### Changes
612

7-
* Reset sort when using `find-cursor.count` due to internal code using projection with `{ _id: 1 }`.
13+
- Reset sort when using `find-cursor.count` due to internal code using projection with `{ _id: 1 }`.
814

915
## 1.0.5 (2024-07-09)
1016

1117
### Add
1218

13-
* Add integration test for `collection.count`, `find-cursor.count` and `find-cursor.sort`.
14-
* Add support for the `mongodb@6.8.0` driver and up.
19+
- Add integration test for `collection.count`, `find-cursor.count` and `find-cursor.sort`.
20+
- Add support for the `mongodb@6.8.0` driver and up.
1521

1622
### Changes
1723

18-
* Use a projection to count documents.
24+
- Use a projection to count documents.
1925

2026
## 1.0.4 (2024-07-04)
2127

2228
### Fix
2329

24-
* Update package-lock.json to reflect package.json content.
30+
- Update package-lock.json to reflect package.json content.
2531

2632
## 1.0.3 (2024-06-28)
2733

2834
### Fix
2935

30-
* Lock to `mongodb@6.7.0` to prevent issues with `cursor.count` not using the current query filter.
36+
- Lock to `mongodb@6.7.0` to prevent issues with `cursor.count` not using the current query filter.
3137

3238
## 1.0.2
3339

3440
### Fix
3541

36-
* Discard connection options not permitted or required by newer MongoDB drivers. Important for `emulate-mongo-2-driver` which depends on this module.
42+
- Discard connection options not permitted or required by newer MongoDB drivers. Important for `emulate-mongo-2-driver` which depends on this module.
3743

3844
## 1.0.1
3945

4046
### Fix
4147

42-
* Allow `FindCursor.sort` with `false` as sort key.
48+
- Allow `FindCursor.sort` with `false` as sort key.
4349

4450
## 1.0.0
4551

‎packages/emulate-mongo-3-driver/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "@apostrophecms/emulate-mongo-3-driver",
3-
"version": "1.0.6",
3+
"version": "1.0.7",
44
"description": "Emulate the Mongo 3.x nodejs driver on top of the Mongo 6.x nodejs driver, for bc",
55
"main": "index.js",
66
"scripts": {

‎packages/font-size/CHANGELOG.md‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
# @apostrophecms/font-size
2+
3+
## 1.0.0 (2026-07-10)
4+
5+
### Adds
6+
7+
- Initial release.

‎packages/form/CHANGELOG.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,11 @@
11
# Changelog
22

3+
## 1.5.4 (2026-07-10)
4+
5+
### Security
6+
7+
- File attachments are no longer stored before a form submission passes validation (GHSA-rgg4-476q-xgcg). Previously, when a submission was rejected — for example due to a failed reCAPTCHA challenge or a missing required field — any uploaded files had already been written as publicly accessible attachments, and those orphaned records were never reclaimed by garbage collection. Submissions are now rejected before any files are stored, and any attachments created while processing a submission that is ultimately rejected are removed. Thanks to [H3xV0rT3x](https://github.com/H3xV0rT3x) for reporting this issue.
8+
39
## 1.5.3 (2026-02-18)
410

511
### Adds

0 commit comments

Comments
 (0)