Sitelet https://github.com/basecamp/writebook/releases
Skip to content

Releases: basecamp/writebook

v1.2.2

Choose a tag to compare

@jeremy jeremy released this 03 Aug 23:30
a5a66e7

What's Changed

Security fixes

Upgrading is recommended for all installations.

  • Page revision history included pages that had been deleted, so their full contents stayed readable to anyone with read access to the book even though the page itself was gone. Revision history is now restricted to editors and excludes deleted pages. (GHSA-29h9-cgxp-w2m9)

  • Uploading into a book's storage was authorized by a token issued when the editor page was rendered, and never re-checked. Someone whose access had been revoked could keep writing files indefinitely. Uploads are now authorized against current access, and the token carries a purpose and an expiry. (GHSA-h97r-8rhg-m67g)

  • Uploaded attachments were served to anyone with the URL and cached publicly for a year, regardless of whether the book was published. Attachments of unpublished books now require access to the book and are no longer publicly cacheable.

Reported by @chroxx-0000, @sps-sdp, @isacaya and @fg0x0. Full details: #463.

Full changelog: v1.2.1...v1.2.2

v1.2.1

Choose a tag to compare

@monorkin monorkin released this 28 Jul 15:23

What's Changed

New Contributors

Full Changelog: v1.2.0...v1.2.1

v1.2.0

Choose a tag to compare

@flavorjones flavorjones released this 15 Apr 15:31
182a76d

Security

  • Delete server-side session on logout — @rosa
  • Sanitize markdown output in edit history and TOC edit views (#392) — @djmb
  • Sanitize search results to prevent XSS from FTS5 output (#420) — @flavorjones

Security-related dependency updates: rack, rack-session, uri, rails-html-sanitizer, nokogiri, addressable.

Features

  • Markdown rendering for books and leaves — appending .md to any book or leaf URL renders it as inline markdown — @dhh
  • YAML frontmatter in markdown views — markdown output includes title, author, and URL metadata — @dhh
  • HTML link tags for markdown alternate format — pages include <link> tags pointing to the markdown version — @dhh
  • Use relative links for uploaded files — uploaded file URLs are now relative, improving portability — @kevinmcconnell

Other