Skip to content

Commit ffa58b3

Browse files
boutellmyovchevBoDonkeyharounstuartromanek
authored
mergeback (#5409)
* Latest merge prerelease 2026 05 (#5404) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> (cherry picked from commit 9f458b5) * Bump CLI dependencies (#5383) (cherry picked from commit a5e1a4a) * Native browser shortcuts work again (#5384) (cherry picked from commit b9b32bd) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments (cherry picked from commit 08845c5) * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> (cherry picked from commit d45e27f) * merge back the thanks (#5388) (cherry picked from commit f3501f4) * ignore inline table array as draggable ui for windows (#5392) (cherry picked from commit b360b05) * Layout focus orchestration (#5393) (cherry picked from commit 77a2968) * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures (cherry picked from commit 008417f) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed (cherry picked from commit e9b3bac) * Layout editable gap (#5397) (cherry picked from commit bc8f7be) * a11y fixes (#5401) (cherry picked from commit 2e2f3b4) * clarifications (#5403) (cherry picked from commit 13f2c69) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Latest security merge (#5407) * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * Merge commit from fork * Merge commit from fork * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * release only (changelogs formatted) (#5408) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com>
1 parent 8098017 commit ffa58b3

10 files changed

Lines changed: 86 additions & 21 deletions

File tree

‎packages/apostrophe-astro/CHANGELOG.md‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,12 @@
11
# Changelog
22

3+
## 1.12.0
4+
5+
### Adds
6+
7+
- Editors can now control the layout-widget gap through the styles system, both site-wide via a global `layoutGap` preset and per widget via a `gap` styles field. New Layout widget option `className` allows for additional CSS class names to be added to the widget Grid container.
8+
- Log aposResponse errors server side in the Astro process. Thanks to [Harouna Traore](https://github.com/haroun).
9+
310
## 1.11.0 (2026-04-15)
411

512
### Adds

‎packages/apostrophe-astro/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "@apostrophecms/apostrophe-astro",
3-
"version": "1.11.0",
3+
"version": "1.12.0",
44
"type": "module",
55
"description": "Apostrophe integration for Astro",
66
"repository": {

‎packages/apostrophe/CHANGELOG.md‎

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,39 @@
11
# Changelog
22

3+
## 4.30.0
4+
5+
### Adds
6+
7+
- Layout widget gap is now controllable through the styles system, both site-wide via a global `layoutGap` preset and per widget via a `gap` styles field. A new `className` option allows additional CSS classes to be added to the widget grid container.
8+
9+
### Fixes
10+
11+
- Fixed layout widget not regaining full focus when switching back to Edit content mode.
12+
- Fixed illegal HTML `id` attribute values generated by the admin UI.
13+
- Fixed orderable table array items dragging the entire floating window.
14+
- Fixed keyboard shortcuts for widget operations (copy, cut, paste, duplicate, remove) blocking the browser's native clipboard behavior when no widget was focused. Previously, selecting and copying text while logged in was intercepted unconditionally by the admin UI.
15+
- Removed duplicate `<meta charset>` tag from `outerLayoutBase.html` and standardized charset to `utf-8`.
16+
- Updated `apostrophe` and `oembetter` to remove oembed services that no longer support public access, eliminating them as a potential future XSS vector. New `minimumAllowlist` and `minimumEndpoints` options on `@apostrophecms/oembed` allow developers to prune the list further.
17+
18+
### Security
19+
20+
- **Password reset base URL requirement:** The password reset feature now refuses to operate unless `baseUrl` or `APOS_BASE_URL` is set, preventing a vulnerability where ApostropheCMS could be convinced to send emails with links to attacker-controlled sites. Only affects projects with `passwordReset: true` on the login module. Thanks to [SPIDY](https://github.com/Mujahidkhan525) for reporting.
21+
- **XSS via full name field:** A malicious full name containing HTML was executed in the page title tooltip in the admin bar, posing an XSS risk to other users. All multi-user projects should update promptly. Thanks to [Muhammad Uwais](https://github.com/MuhammadUwais) for reporting.
22+
- **XSS via image widget link URL:** Users with editing privileges could trigger arbitrary JavaScript via a `javascript:` URL in the image widget's link URL field. A migration is included to strip any such URLs already in the database. Thanks to [Muhammad Uwais](https://github.com/MuhammadUwais) for reporting.
23+
- **SSRF via rich text HTML import:** The rich text widget's HTML import feature no longer fetches images from arbitrary hosts, which could be used to probe internal networks or exfiltrate internal images. Configure `imageImportAllowedHostnames` on `@apostrophecms/rich-text-widget` to opt in. Thanks to [Yiğit Şengezer](https://github.com/yigitsengezer) and [Sainithin0309](https://github.com/Sainithin0309) for reporting.
24+
- **the xmp tag could be used to pass forbidden markup through sanitize-html**, even when xmp itself. This was fixed in `sanitize-html` and the dependency was bumped. Thanks to [Vincenzo Turturro](https://github.com/sushi-gif) for reporting the vulnerability.
25+
- **the `linkHref` field of image widgets was an XSS vulnerability** because it did not use the `url` field type. This means that a user with editing privileges could potentially carry out XSS. In addition, we have updated the `launder` module to sanitize URLs more robustly for the `url` field type, and bumped that dependency. Also, a database migration is included to clean any XSS attacks that could be present in existing links. Thanks to [Muhammad Uwais](https://github.com/MuhammadUwais) for reporting the issue.
26+
27+
### Accessibility
28+
29+
- Corrected ARIA semantics on the top admin navigation bar.
30+
- Improved the document context title (admin bar middle group) and the underlying `AposContextMenu` machinery.
31+
- Improved the locale switcher (`AposLocalePicker`).
32+
- The Recently Edited Documents tray icon now exposes its action via `aria-label`.
33+
- Fixed `.apos-sr-only` so screen-reader-only content is correctly exposed to the accessibility tree.
34+
- Icon-only context-utility buttons in the admin bar tray (e.g. the global settings cog) now expose their action via `aria-label`.
35+
36+
337
## 4.29.0 (2026-04-15)
438

539
### Adds

‎packages/apostrophe/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "apostrophe",
3-
"version": "4.29.0",
3+
"version": "4.30.0",
44
"description": "The Apostrophe Content Management System.",
55
"main": "index.js",
66
"scripts": {

‎packages/cli/CHANGELOG.md‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,12 @@
11
# Changelog
22

3+
## 3.6.1
4+
5+
### Security
6+
7+
- Bump and clean up dependencies. This closes vulnerabilities in `uuid` and `fast-xml-parser` although they were not used in a sensitive or vulnerable way within ApostropheCMS. This also closes a vulnerability in `shelljs` which ould only be exploited if the developer could be convinced to enter malicious commands as part of their CLI input.
8+
- Passwords and starter kit URLs containing intentionally malicious punctuation cannot be used to run arbitrary shell commands. Because the CLI is only used by developers, this would always have been an "own goal" situation, however this does make the CLI more robust for scripted use. Thanks to [Nitro13urn](https://github.com/VadlaReddySai) for reporting the issue.
9+
310
## 3.6.0 (2026-02-18)
411

512
### Adds
@@ -11,6 +18,7 @@
1118
- The `add` command now displays an error when run inside a hybrid Astro project, as it is not currently supported in that context.
1219

1320
- The default starter kit is now `public-demo`
21+
1422
- Validates the `shortName` argument in the `create` command to only allow letters, numbers, hyphens, and underscores, preventing potential command injection.
1523

1624
## 3.5.0 (2025-01-07)

‎packages/cli/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "@apostrophecms/cli",
3-
"version": "3.6.0",
3+
"version": "3.6.1",
44
"description": "Commandline generator and configurator for Apostrophe CMS",
55
"main": "bin/apostrophe",
66
"scripts": {

‎packages/launder/CHANGELOG.md‎

Lines changed: 22 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,67 +1,73 @@
11
# Changelog
22

3+
## 1.7.1
4+
5+
### Security
6+
7+
- `launder` now uses and exports the best available naughtyHref function for detecting malicious URLs. sanitize-html now depends on it, and apostrophe now uses type: 'url' for the link URL field of image widgets, which leverages it. Prior to this fix, it was possible for any user with editing privileges, including a contributor, to trigger arbitrary JavaScript via a javascript: URL in the link URL field of an image widget. A migration has been included to strip any such malicious URLs already present in the database. All users of apostrophe are encouraged to upgrade to get this security fix. Thanks to [Muhammad Uwais](https://github.com/MuhammadUwais) for reporting the issue.
8+
39
## 1.7.0 - 2023-05-03
410

5-
* Modernize dependencies to correct installation warnings, and eliminate use of `var`.
11+
- Modernize dependencies to correct installation warnings, and eliminate use of `var`.
612

713
## 1.6.0 - 2023-03-06
814

9-
* `sms:` urls are now accepted. Thanks to [Ruben](https://github.com/reubendsouza) for this change.
15+
- `sms:` urls are now accepted. Thanks to [Ruben](https://github.com/reubendsouza) for this change.
1016

1117
## 1.5.1 - 2021-10-28
1218

13-
* The `date` method now correctly returns `null` if the date argument is unparseable and the `def` parameter is explicitly `null`. As was always documented, a default of `undefined` still returns the current date.
19+
- The `date` method now correctly returns `null` if the date argument is unparseable and the `def` parameter is explicitly `null`. As was always documented, a default of `undefined` still returns the current date.
1420

1521
## 1.5.0
1622

17-
* The `url` method now accepts a third argument, `httpsFix`. If it is `true` and the URL passed in has no protocol, the URL will be prepended with `https://` rather than `http://`.
23+
- The `url` method now accepts a third argument, `httpsFix`. If it is `true` and the URL passed in has no protocol, the URL will be prepended with `https://` rather than `http://`.
1824

1925
## 1.4.0
2026

21-
* `tel:` urls are now accepted.
27+
- `tel:` urls are now accepted.
2228

2329
## 1.3.0
2430

25-
* `booleanOrNull` accepts the string `'null'` as a synonym for `null`. Note that `'any'` was already accepted. `'null'` can be an attractive choice when the user will not see it in the query string and conflict with other uses of `'any'` is a concern.
31+
- `booleanOrNull` accepts the string `'null'` as a synonym for `null`. Note that `'any'` was already accepted. `'null'` can be an attractive choice when the user will not see it in the query string and conflict with other uses of `'any'` is a concern.
2632

2733
## 1.2.0
2834

29-
* `idRegExp` option may be passed to change the rules for `launder.id`.
35+
- `idRegExp` option may be passed to change the rules for `launder.id`.
3036

3137
## 1.1.2
3238

33-
* linting.
39+
- linting.
3440

3541
## 1.1.1
3642

37-
* for improved bc, `launder.select` does not crash if some of the choices given to `select` are null or undefined. Although this is a developer error rather than a sanitization issue, versions prior to 1.1.0 did tolerate this situation, so 1.1.1 does so as well. Thanks to Anthony Tarlao for his code contributions, and to Michelin for making this fix possible via [Apostrophe Enterprise Support](https://apostrophecms.com/support/enterprise-support).
43+
- for improved bc, `launder.select` does not crash if some of the choices given to `select` are null or undefined. Although this is a developer error rather than a sanitization issue, versions prior to 1.1.0 did tolerate this situation, so 1.1.1 does so as well. Thanks to Anthony Tarlao for his code contributions, and to Michelin for making this fix possible via [Apostrophe Enterprise Support](https://apostrophecms.com/support/enterprise-support).
3844

3945
## 1.1.0
4046

41-
* `launder.select` now handles numeric values for choices gracefully. Specifically, if the value passed in is a string, it will be validated as a match for a choice that is a number, as long as they have the same string representation, and the number (not the string) will be returned. Previously there was no match in this situation.
47+
- `launder.select` now handles numeric values for choices gracefully. Specifically, if the value passed in is a string, it will be validated as a match for a choice that is a number, as long as they have the same string representation, and the number (not the string) will be returned. Previously there was no match in this situation.
4248

4349
Thanks to Michelin for making this possible via [Apostrophe Enterprise Support](https://apostrophecms.com/support/enterprise-support).
4450

4551
## 1.0.1
4652

47-
* `launder.time` will now also accept a `.` (dot) as the separator (until now only `:` colon was recognized). Thanks to Lars Houmark.
53+
- `launder.time` will now also accept a `.` (dot) as the separator (until now only `:` colon was recognized). Thanks to Lars Houmark.
4854

4955
## 1.0.0
5056

51-
* switched to a maintained, secure fork of lodash 3, declared 1.0.0 as this has been a stable part of Apostrophe for years.
57+
- switched to a maintained, secure fork of lodash 3, declared 1.0.0 as this has been a stable part of Apostrophe for years.
5258

5359
## 0.1.3
5460

55-
* `launder.booleanOrNull` broken out from `launder.addBooleanFilterCriteria` so that you can get the tri-state value without modifying a criteria object.
61+
- `launder.booleanOrNull` broken out from `launder.addBooleanFilterCriteria` so that you can get the tri-state value without modifying a criteria object.
5662

5763
## 0.1.2
5864

59-
* `launder.tags` also accepts a comma-separated string.
65+
- `launder.tags` also accepts a comma-separated string.
6066

6167
## 0.1.1
6268

63-
* removed never-used and undocumented `parseTime` method.
69+
- removed never-used and undocumented `parseTime` method.
6470

6571
## 0.1.0
6672

67-
* initial release. Based on stable code recently refactored from Apostrophe 0.5.x.
73+
- initial release. Based on stable code recently refactored from Apostrophe 0.5.x.

‎packages/launder/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "launder",
3-
"version": "1.7.0",
3+
"version": "1.7.1",
44
"description": "A sanitize module for the people. Built for ApostropheCMS.",
55
"main": "index.js",
66
"scripts": {

‎packages/sanitize-html/CHANGELOG.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,15 @@
11
# Changelog
22

3+
## 2.17.4
4+
5+
### Changes
6+
7+
- `sanitize-html` and `launder` now share a single implementation of `naughtyHref`, based on that which previously existed in `sanitize-html`.
8+
9+
### Security
10+
11+
- Security vulnerability: the xmp tag could be used to pass forbidden markup through sanitize-html, even when xmp itself is not explicitly allowed All users of sanitize-html should update immediately. Thanks to [Vincenzo Turturro](https://github.com/sushi-gif) for reporting the vulnerability.
12+
313
## 2.17.3 (2026-04-15)
414

515
### Security

‎packages/sanitize-html/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "sanitize-html",
3-
"version": "2.17.3",
3+
"version": "2.17.4",
44
"description": "Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis",
55
"sideEffects": false,
66
"main": "index.js",

0 commit comments

Comments
 (0)