Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions packages/apostrophe-astro/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,14 @@
# Changelog

## 1.13.0 (2026-06-10)

### Fixes

- Adding or removing an area field from a schema no longer breaks documents on an external front such as Astro.
- `AposArea` now renders only schema-backed areas. A missing area no longer throws, and an area orphaned by removing its field from the schema (while its content remains in the document) renders nothing instead of breaking sibling areas in edit mode. Logged-in editors get a diagnostic message in place of an orphaned area; anonymous visitors see nothing.
- Editable documents sent to an external front now materialize empty area objects for schema area fields added after the document was created, so they can be edited in context.
- `apos.util.getManagerOf` accepts a `{ log }` option to suppress its error log when probing objects that may not have a manager.

## 1.12.0

### Adds
Expand Down
2 changes: 1 addition & 1 deletion packages/apostrophe-astro/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@apostrophecms/apostrophe-astro",
"version": "1.12.0",
"version": "1.13.0",
"type": "module",
"description": "Apostrophe integration for Astro",
"repository": {
Expand Down
29 changes: 27 additions & 2 deletions packages/apostrophe/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,31 @@
# Changelog

## 4.31.0 (2026-06-10)

### Adds

- Added support for `draggable: false` on non-inline `array` schema fields. Previously this option was only respected when `inline: true`. When set on a standard (modal-based) array field, drag-and-drop reordering and keyboard reordering are now disabled in the array editor's slat list.
- Introduced support for postgres://, sqlite://, and multipostgres:// database URIs in addition to mongodb://. The new db-connect API supports all of the database operations currently used in our own core, pro and multisite modules. For more information see the documentation.
- JSX support for templates within ApostropheCMS. JSX is now co-equal with Nunjucks, with a gradual migration strategy. Anyone who is familiar with React will be very comfortable writing JSX templates, which also offer a superior debugging experience, and templates can be migrated gradually. JSX is a great option for those who don't wish to create parallel Astro and ApostropheCMS projects, but still prefer a modern syntax. For more information, see the new [JSX templates guide](https://apostrophecms.com/docs/guide/jsx-templates.html).
- The session secret and the uploadfs `disabledFileKey` can now be supplied via the `APOS_SESSION_SECRET` and `APOS_UPLOADFS_DISABLED_FILE_KEY` environment variables. As with other Apostrophe environment variables, these take precedence over the corresponding `app.js` configuration.

### Fixes

- Fixed an issue where using the Tab key to navigate within modals could incorrectly jump focus to a wrong element instead of the next input field.
Fixed Tab navigation escaping out of modals when the form contained hidden sections or elements that became disabled after editing.
- Fixed adding or removing an area field from a schema breaking existing documents on an external front such as Astro.
- For Astro: `AposArea` now renders only schema-backed areas. A missing area no longer throws, and an area orphaned by removing its field from the schema (while its content remains in the document) renders nothing instead of breaking sibling areas in edit mode. Logged-in editors get a diagnostic message in place of an orphaned area; anonymous visitors see nothing.
- Editable documents sent to an external front (Asgtro) now materialize empty area objects for schema area fields added after the document was created, so they can be edited in context.
- `apos.util.getManagerOf` accepts a `{ log }` option to suppress its error log when probing objects that may not have a manager.
- Fix more admin UI a11y issues.
- Selecting an item in a relationship "browse" dialog no longer scrolls the title and Cancel/Select buttons out of view when the item is far down the list.
- Sites with a custom filterByIndexPage method no longer experience failures in the sitemap module and potential creeping CPU performance penalties. A regression introduced with our static site support, but not specific to static sites.

### Security

- Server-side prototype pollution (CWE-1321) via dot-notation paths. `apos.util.set()` and `apos.util.get()` now refuse to traverse `__proto__`, `constructor` and `prototype` path segments. Previously an authenticated editor could send a PATCH REST API request whose patch operators (for example `$pullAll` with a key of `__proto__.publicApiProjection`) wrote to `Object.prototype`. A polluted `publicApiProjection` defeated the `publicApiCheck()` authorization gate on piece-type REST endpoints for subsequent unauthenticated requests, for the lifetime of the Node.js process. All users should update. Thanks to [tonghuaroot](https://github.com/tonghuaroot), [H3xV0rT3x](https://github.com/H3xV0rT3x), and [5h1kh4r](https://github.com/5h1kh4r) for reporting the vulnerability.
- When `@apostrophecms/file` pretty URLs are enabled (`prettyUrls: true`), the upstream request used to serve the file is no longer built from the incoming `Host` header. The self-request is now resolved against the site's configured `baseUrl` (via `req.baseUrl`), falling back to the request host only when no `baseUrl` is configured. This closes a server-side request forgery (SSRF) vector in which the `Host` header could steer the proxied fetch at another host. The real-world risk was low: the path is constrained to an existing attachment's `/uploads/attachments/<cuid>-<slug>.<ext>`, and cuids are unique and immutable, so any reachable content was already public via the front door. Thanks to [EchoSkorJjj](https://github.com/EchoSkorJjj) for reporting the issue.

## 4.30.0

### Adds
Expand All @@ -21,7 +47,7 @@
- **XSS via full name field:** A malicious full name containing HTML was executed in the page title tooltip in the admin bar, posing an XSS risk to other users. All multi-user projects should update promptly. Thanks to [Muhammad Uwais](https://github.com/MuhammadUwais) for reporting.
- **XSS via image widget link URL:** Users with editing privileges could trigger arbitrary JavaScript via a `javascript:` URL in the image widget's link URL field. A migration is included to strip any such URLs already in the database. Thanks to [Muhammad Uwais](https://github.com/MuhammadUwais) for reporting.
- **SSRF via rich text HTML import:** The rich text widget's HTML import feature no longer fetches images from arbitrary hosts, which could be used to probe internal networks or exfiltrate internal images. Configure `imageImportAllowedHostnames` on `@apostrophecms/rich-text-widget` to opt in. Thanks to [Yiğit Şengezer](https://github.com/yigitsengezer) and [Sainithin0309](https://github.com/Sainithin0309) for reporting.
- **the xmp tag could be used to pass forbidden markup through sanitize-html**, even when xmp itself. This was fixed in `sanitize-html` and the dependency was bumped. Thanks to [Vincenzo Turturro](https://github.com/sushi-gif) for reporting the vulnerability.
- **the xmp tag could be used to pass forbidden markup through sanitize-html**, even when xmp itself. This was fixed in `sanitize-html` and the dependency was bumped. Thanks to [Vincenzo Turturro](https://github.com/sushi-gif) for reporting the vulnerability.
- **the `linkHref` field of image widgets was an XSS vulnerability** because it did not use the `url` field type. This means that a user with editing privileges could potentially carry out XSS. In addition, we have updated the `launder` module to sanitize URLs more robustly for the `url` field type, and bumped that dependency. Also, a database migration is included to clean any XSS attacks that could be present in existing links. Thanks to [Muhammad Uwais](https://github.com/MuhammadUwais) for reporting the issue.

### Accessibility
Expand All @@ -33,7 +59,6 @@
- Fixed `.apos-sr-only` so screen-reader-only content is correctly exposed to the accessibility tree.
- Icon-only context-utility buttons in the admin bar tray (e.g. the global settings cog) now expose their action via `aria-label`.


## 4.29.0 (2026-04-15)

### Adds
Expand Down
2 changes: 1 addition & 1 deletion packages/apostrophe/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "apostrophe",
"version": "4.30.0",
"version": "4.31.0",
"description": "The Apostrophe Content Management System.",
"main": "index.js",
"scripts": {
Expand Down
6 changes: 6 additions & 0 deletions packages/cli/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,11 @@
# Changelog

## 3.7.0 (2026-06-10)

### Adds

- `apos create` is now an interactive guided installer (it delegates to `create-apostrophe`). The `<shortname>` positional argument and the `--starter` and `--mongodb-uri` options have been removed - project name, starter kit, and database are now chosen through prompts. For scripted installs, use `npm create apostrophe@latest -- --unattended` instead.

## 3.6.1

### Security
Expand Down
2 changes: 1 addition & 1 deletion packages/cli/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@apostrophecms/cli",
"version": "3.6.1",
"version": "3.7.0",
"description": "Commandline generator and configurator for Apostrophe CMS",
"main": "bin/apostrophe",
"scripts": {
Expand Down
6 changes: 6 additions & 0 deletions packages/import-export/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,11 @@
# Changelog

## 3.6.1 (2026-06-10)

### Changes

- 04d3053: Debug logging is now disabled by default and can be enabled by setting the `debug: true` option on the `@apostrophecms/import-export` module, or by setting the `APOS_DEBUG_IMPORT_EXPORT=1` environment variable.

## 3.6.0

### Changes
Expand Down
2 changes: 1 addition & 1 deletion packages/import-export/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@apostrophecms/import-export",
"version": "3.6.0",
"version": "3.6.1",
"description": "Import Export Documents for ApostropheCMS",
"main": "index.js",
"scripts": {
Expand Down
36 changes: 21 additions & 15 deletions packages/redirect/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,35 +1,41 @@
# Changelog

## 1.6.0 (2026-06-10)

### Fixes

- 958d162: Prevent infinite redirects to external URLs

## 1.5.0 (2025-11-25)

* Support for wildcards. See the README for more information.
- Support for wildcards. See the README for more information.

## 1.4.3 (2025-09-03)

* Bug fix: UTF8 URLs now match properly. For instance, redirects containing Thai characters work as expected. Editors can paste them naturally (without hand-escaping them first) and the redirect module will correctly decode the URL received from Express before attempting to match it to a redirect.
- Bug fix: UTF8 URLs now match properly. For instance, redirects containing Thai characters work as expected. Editors can paste them naturally (without hand-escaping them first) and the redirect module will correctly decode the URL received from Express before attempting to match it to a redirect.

## 1.4.2 (2024-10-03)

* Updates translations strings
- Updates translations strings

## 1.4.1 (2024-03-20)

* Bug fix to properly migrate older redirects missing a `targetLocale` property, and to tolerate situations where this property is irrelevant or makes reference to a locale that no longer exists in the system.
* Fixes permanent redirects (301) being 302 because `statusCode` of the redirects were never fetched.
* README and package description updated.
- Bug fix to properly migrate older redirects missing a `targetLocale` property, and to tolerate situations where this property is irrelevant or makes reference to a locale that no longer exists in the system.
- Fixes permanent redirects (301) being 302 because `statusCode` of the redirects were never fetched.
- README and package description updated.

## 1.4.0 (2024-02-23)

Several fixes and improvements contributed by Stéphane Maccari of Michelin:

* Add a way to modify the target url before doing the redirection
* Irrelevant SEO fields are properly removed from redirect pieces
* The `ignoreQueryString` field is honored properly
* Redirects to internal pages are saved properly
* Admins adding redirects may now elect to pass on the query string as part of the redirect
* `before` option added, giving the option of running the middleware earlier, e.g. before `@apostrophecms/global`
* Performance enhancement: skip the redirect check for API URLs like `/api/v1/...`. This can be
overridden using the `skip` option
- Add a way to modify the target url before doing the redirection
- Irrelevant SEO fields are properly removed from redirect pieces
- The `ignoreQueryString` field is honored properly
- Redirects to internal pages are saved properly
- Admins adding redirects may now elect to pass on the query string as part of the redirect
- `before` option added, giving the option of running the middleware earlier, e.g. before `@apostrophecms/global`
- Performance enhancement: skip the redirect check for API URLs like `/api/v1/...`. This can be
overridden using the `skip` option

Many thanks for this contribution.

Expand Down Expand Up @@ -59,11 +65,11 @@ Many thanks for this contribution.
- Adds Spanish (`es`) localization to static text. Thanks to [Eugenio Gonzalez](https://github.com/egonzalezg9) for the contribution.
- Adds Slovak (`sk`) locale strings for static text. Thanks to [Michael Huna](https://github.com/Miselrkba) for the contribution.


## 1.0.1 (2021-08-26)

- Localization is inappropriate for redirects since it's necessary to be able to redirect from any URL. Previously `autopublish: true` was used by the module, but `localize: false` is more appropriate as it eliminates multiple locale versions altogether. A migration has been added to take care of existing redirects in this transition.
- Fixes README code examples for the `withType` and `statusCode` options.

## 1.0.0

- Initial port from Apostrophe 2.0
2 changes: 1 addition & 1 deletion packages/redirect/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@apostrophecms/redirect",
"version": "1.5.0",
"version": "1.6.0",
"description": "Manage redirects for apostropheCMS",
"main": "index.js",
"scripts": {
Expand Down
7 changes: 7 additions & 0 deletions packages/sanitize-html/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,12 @@
# Changelog

## 2.17.5 (2026-06-10)

### Security

- Added a number of new attributes to be protected against unsafe URLs, e.g. `javascript:` and similar. None of these are used in the default configuration of `sanitize-html` or `apostrophe` or likely to be used there, and some attributes, like an `action` for a `form`, are inherently unsafe to allow if XSS protection is your goal. Nevertheless it makes sense to block certain URL types where they are not appropriate. Some attributes are not supported at all by modern browsers but are included for completeness. Thanks to [crattack](https://github.com/crattack) for reporting the vulnerability.
- Address a potential vulnerability when nonTextTags is configured in a nonstandard way. While it is never a good idea to remove known non-text tags from the standard list e.g. script, styles, etc., this change ensures that doing so does not result in nested tags being passed through without sanitization when they are not expressly allowed. (ApostropheCMS would never trigger this situation.) Thanks to [Dipanshu singh](https://github.com/Dipanshusinghh) for pointing out the issue and contributing the fix.

## 2.17.4

### Changes
Expand Down
2 changes: 1 addition & 1 deletion packages/sanitize-html/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "sanitize-html",
"version": "2.17.4",
"version": "2.17.5",
"description": "Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis",
"sideEffects": false,
"main": "index.js",
Expand Down
14 changes: 14 additions & 0 deletions packages/seo/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,19 @@
# Changelog

## 1.5.0 (2026-06-10)

### Adds

- 958d162: Removes unimplemented hreflang output; use @apostrophecms/sitemap for hreflang support

### Changes

- 958d162: Removes the `seoSiteCanonicalUrl` field from global settings. The base URL is now derived automatically from `APOS_BASE_URL` or the `baseUrl` option. The value remains available at `req.data.global.seoSiteCanonicalUrl` for backwards compatibility.

### Security

- The Google Analytics tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) global SEO fields were interpolated directly into the bodies of inline `<script>` tags without escaping. Any user permitted to edit the global document, including editors and contributors (if their submission were approved), could set these fields to a value that broke out of the surrounding script and executed arbitrary JavaScript for every visitor on every page (stored XSS). These values are now emitted as escaped `json` nodes, matching the JSON-LD handling, so they can no longer terminate the `<script>` element or escape the string literal they sit in. All projects using `@apostrophecms/seo` with untrusted editors should upgrade promptly to close this vulnerability. Thanks to [H3xV0rT3x](https://github.com/H3xV0rT3x) and [hibrian827](https://github.com/hibrian827) for reporting the issue.

## 1.4.2

### Security
Expand Down
2 changes: 1 addition & 1 deletion packages/seo/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@apostrophecms/seo",
"version": "1.4.2",
"version": "1.5.0",
"description": "SEO Tools for ApostropheCMS",
"main": "index.js",
"scripts": {
Expand Down
Loading