ready for 4.32.0 release - #5513
Merged
Merged
Conversation
* Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com>
* Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments
* log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com>
* postgres experimental WIP
* astonishingly, all mocha tests of apostrophe pass with this
* mocha tests pass, actual sites work
* lint clean
* listDatabases support, but changes are coming
* wip
* dump and restore updates
* backpressure, adequate handling of ObjectId for our needs (becomes its hex representation)
* mild performance optimization
* profiling
* testing issue resolved
* refactored to db-connect module, introduced sqlite adapter
* sqlite WIP
* debugging
* programmatic API for dump/restore/copy dbs
* linting, documentation
* MIT license
* text ranking is more accurate, documentation is more complete
* good full text search for sqlite
* updates for compatibility with the rest of the public and private modules, plus a few fixes to genuinely ambiguous tests
* requirements found by testing private modules
* fixes from full cypress run
* eslint passing
* restore permissions
* maximize atomicity
* bug fixes
* * exit properly when asset tests fail
* "npm test" tests all three adapters
* ignore claude-tools in eslint
* postgres and sqlite-inclusive ci matrix attempt
* clean up logs
* We hit github's limit on total configurations because every package gets its own matrix.
Solve that with grouping:
* apostrophe core
* All regular ecosystem packages other than core
* non-database-requiring packges
* mongodb-specific packages
This will probably speed it up too because it won't have to spin up a container a bazillion times.
* hardened the asset tests, made them less timing sensitive, fixed a bad commit resulting from the
way they dodgily patch themselves without a robust cleanup mechanism
* fix a root cause of asset test instability
* log mess
* implemented missing $size operator
* test compatibility
* advanced permission uses regex in $in
* regex in $in
* .db() should not make false promises in plain postgres mode, it should fail
* ability to specify a default adapter
* obsolete file
* put escapeHost back where it belongs
* dead code removal, test cleanup
* emulate-mongo-3-driver only needed in db-connect
* no claude logs in repo (tools are welcome)
* * shared aggregation implementation, other shared things
* optimize $match when it is the first step in aggregation, don't fetch the whole collection 😜
* multipostgres listDatabases() and .db() should return and expect "fully qualified virtual database names," e.g. physical_db_name-schemaname
* vanilla postgres should not attempt to use .db() with alternate names in tests
* documentation corrections
* documentation errors
* listDatabases and documentation corrections
* more edge cases revealed by latest work from Miro
* anchored prefix regexps are optimized
documentation improvements
* * matchesQuery in the aggregation cursor implementation doesn't throw on unrecognized operators. It should, and it should support the same mongodb operators that the regular find()
path does in postgres/sqlite (our official subset), unless there is an extraordinary reason not to.
* Similarly, the main query implementation for normal queries should throw on unrecognized operators if it doesn't already.
* The dump/restore programmatic APIs in db-connect concern me. These involve returning the entire database as a string, which could exhaust memory. This impacts both utilities and
also copyDatabase(). Could these APIs return and expect async iterators instead of strings?
* The test "anchored regex on an indexed field uses a btree index search" runs explain on a query that's hardcoded in the test. Instead these SQL based adapters should expose a means
to get the SQL for a query, so it can be directly tested. Otherwise this test proves nothing as changes to the adapter accumulate in future.
* Why is this test searching for "at least 1" and not exactly 1?
it('should find documents with null value', async function() {
const docs = await db.collection('test').find({ value: null }).toArray();
// MongoDB matches both null and missing fields with { value: null }
expect(docs.length).to.be.at.least(1);
});
* What is the maximum size of a db-connect document in the postgres and sqlite adapters?
* Update the copyright year in db-connect/LICENSE.md to 2025.
* The db-connect README mentions: sqlite://:memory: What happens if you try to use .db('some-name') with that? I think it would be best to just not support throwaway in-memory sqlite
databases because I doubt anyone would intentionally store a website in one.
* do not swallow dump/restore errors on indexes
* cover how to run the utilities
* fix detection of source
* separate sanitization for index names
* regex prefix safety
* pnpm
---------
Co-authored-by: Thomas Boutell <boutell@vcs.trox.local>
* Remove hreflang generation and update README * Add changeset * Changeset update
* Removes `seoSiteCanonicalUrl` * Update tests and remove missed log * Change semver level
* Bump dependencies * Fix missing test await resulting in random failures
* Remove hreflang generation and update README * Add changeset * Changeset update
…eveloper control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed
* Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset
* fix xmp tag vulnerability * thanks
* secure the link URL field of image widgets * credit
* Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter
* Latest merge prerelease 2026 05 (#5404) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> (cherry picked from commit 9f458b5) * Bump CLI dependencies (#5383) (cherry picked from commit a5e1a4a) * Native browser shortcuts work again (#5384) (cherry picked from commit b9b32bd) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments (cherry picked from commit 08845c5) * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> (cherry picked from commit d45e27f) * merge back the thanks (#5388) (cherry picked from commit f3501f4) * ignore inline table array as draggable ui for windows (#5392) (cherry picked from commit b360b05) * Layout focus orchestration (#5393) (cherry picked from commit 77a2968) * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures (cherry picked from commit 008417f) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed (cherry picked from commit e9b3bac) * Layout editable gap (#5397) (cherry picked from commit bc8f7be) * a11y fixes (#5401) (cherry picked from commit 2e2f3b4) * clarifications (#5403) (cherry picked from commit 13f2c69) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Latest security merge (#5407) * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * Merge commit from fork * Merge commit from fork * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * release only (changelogs formatted) (#5408) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com>
* Latest merge prerelease 2026 05 (#5404) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> (cherry picked from commit 9f458b5) * Bump CLI dependencies (#5383) (cherry picked from commit a5e1a4a) * Native browser shortcuts work again (#5384) (cherry picked from commit b9b32bd) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments (cherry picked from commit 08845c5) * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> (cherry picked from commit d45e27f) * merge back the thanks (#5388) (cherry picked from commit f3501f4) * ignore inline table array as draggable ui for windows (#5392) (cherry picked from commit b360b05) * Layout focus orchestration (#5393) (cherry picked from commit 77a2968) * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures (cherry picked from commit 008417f) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed (cherry picked from commit e9b3bac) * Layout editable gap (#5397) (cherry picked from commit bc8f7be) * a11y fixes (#5401) (cherry picked from commit 2e2f3b4) * clarifications (#5403) (cherry picked from commit 13f2c69) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Latest security merge (#5407) * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * Merge commit from fork * Merge commit from fork * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * release only (changelogs formatted) (#5408) * allow oembetter to be released (#5412) * release oembetter 1.2.0 (#5413) * release oembetter 1.2.0 * left commit --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com>
* Fix focus trap on the last element in a modal * Fix trap escaping edge cases
* remove noise, switch to utils debug * Fix tests * Introduce debug option * changelog * Fix test sorting issue
* Fix editor modal a11y issues * Fix manager a11y problems * Fix page manager a11y problems * fix media manager a11y issues * fix a11y issues in style editor and user settings * Fix login a11y issues * eliminate a modal issue * Remove bad aria in rich text * Fix wrong aria in layout * changelog * Fix totp a11y issues, doc context state safety * Fix uncaught error - popup blockers/tests
* fromRichText adds metatype to new widget * change
* Migrate node-fetch to built-in fetch (undici), remove the node-fetch dep * Better changelog details, fix IPv6 test issues (CI) * Fix batch total race
* Prepare for npm v12 - create apostrophe * Changelog
* replace virtual modules with generated files, formalize public helper API * Add changeset * Helpers cleanup * Path correction * Add .d.ts and tsconfig files * Remove first design doc * Remove final design doc * Better static cache root dir behavior and docs fix * Refactor for non-bc * Migration and version number * Response to comments. * Deprecate old files * Fixes upgrade header handling * Add tests * Add peerDependencies for Astro v5/v6/v7, drop entryPoint v3 shim * update changeset and literal route * Add response to reviewer comments
* working, but inboard * works, now let's try more of an inline look * screenshot * typo broke image * changeset file so it gets published
…lter is set (#5494) When a transformTags handler adds text to an allowed tag that originally had no text content, the injected text was silently dropped if any textFilter was configured. The onopentag branch that emits frame.innerText was guarded by !options.textFilter, deferring emission to ontext so the filter could run there. For an empty element htmlparser2 never fires ontext, so the text was emitted by neither branch. Emit frame.innerText through options.textFilter here when present (mirroring the discard path), so the transformTags text contract holds for empty tags regardless of whether a textFilter is set.
* Fix backspace after slash deleting a rich-text widget * Fix copy/paste widget/text conflicts
* fix path traversal in import/export * correct credits * additional guards
* wip * fix for math/svg vulnerabilities
BoDonkey
approved these changes
Jul 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.