Skip to content

Commit e62eb55

Browse files
committed
Merge branch 'main' into import-export-noise
2 parents 83fd6cc + 13f2c69 commit e62eb55

43 files changed

Lines changed: 1233 additions & 86 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.changeset/a11y-admin-nav.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"apostrophe": patch
3+
---
4+
5+
Accessibility: corrected ARIA semantics on the top admin navigation bar.

‎.changeset/a11y-context-title.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"apostrophe": patch
3+
---
4+
5+
Accessibility: improvements to the document context title (admin bar middle group) and the underlying `AposContextMenu` machinery.

‎.changeset/a11y-locale-switcher.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"apostrophe": patch
3+
---
4+
5+
Accessibility: improve the locale switcher (`AposLocalePicker`).
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"apostrophe": patch
3+
---
4+
5+
Accessibility: the Recently Edited Documents tray icon (admin bar) now exposes its action through `aria-label`.

‎.changeset/a11y-sr-only.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"apostrophe": patch
3+
---
4+
5+
Accessibility: fix `.apos-sr-only` so screen-reader-only content is exposed to the accessibility tree.

‎.changeset/a11y-tray-aria.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"apostrophe": patch
3+
---
4+
5+
Accessibility: icon-only context-utility buttons in the admin bar tray (e.g. the global settings cog) now expose their action through `aria-label`.

‎.changeset/cozy-wombats-burn.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,4 +2,4 @@
22
"@apostrophecms/cli": patch
33
---
44

5-
Bump and clean up depdendencies.
5+
Security: bump and clean up dependencies. This closes vulnerabilities in `uuid` and `fast-xml-parser` although they were not used in a sensitive or vulnerable way within ApostropheCMS. This also closes a vulnerability in `shelljs` which ould only be exploited if the developer could be convinced to enter malicious commands as part of their CLI input.

‎.changeset/fifty-hornets-follow.md‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
2-
"apostrophe": minor
2+
"apostrophe": patch
33
---
44

55
- Removed duplicate <meta charset> tag from `outerLayoutBase.html`
6-
- Standardized charset to utf-8 (removed legacy configuration option)
7-
- Altered unused/legacy i18n template helper to return `utf-8` (BC)
6+
- Standardized charset to utf-8 (the legacy configuration option is now ignored). Per the spec this is the only legal setting, so we classify this as a bug fix
7+
- Altered unused/legacy i18n template helper to return `utf-8`, ensuring backwards compatibility

‎.changeset/seven-emus-vanish.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
---
2+
"@apostrophecms/apostrophe-astro": minor
3+
"apostrophe": minor
4+
---
5+
6+
Editors can now control the layout-widget gap through the styles system, both site-wide via a global `layoutGap` preset and per widget via a `gap` styles field. New Layout widget option `className` allows for additional CSS class names to be added to the widget Grid container.

‎.changeset/wild-forks-fetch.md‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
---
2+
"apostrophe": patch
3+
---
4+
5+
apostrophe and oembetter have been updated to eliminate a number of services that formerly supported
6+
oembed for the general public, but no longer do so. While there is no security risk today, removing
7+
these ensures that if these domains are ever allowed to lapse, they do not become an XSS
8+
attack vector in the future.
9+
10+
Because oembed responses are not always iframes, it is important that this list be maintained
11+
over time. In addition, developers always have the option to prune it on their own by setting
12+
the new minimumAllowlist and minimumEndpoints options of the @apostrophecms/oembed module.
13+
14+
Thanks to [Sainithin0309](https://github.com/Sainithin0309) for pointing out the potential
15+
long-term security concern.

0 commit comments

Comments
 (0)