Repository navigation
Releases: basecamp/writebook
Release list
v1.2.2
What's Changed
Security fixes
Upgrading is recommended for all installations.
-
Page revision history included pages that had been deleted, so their full contents stayed readable to anyone with read access to the book even though the page itself was gone. Revision history is now restricted to editors and excludes deleted pages. (GHSA-29h9-cgxp-w2m9)
-
Uploading into a book's storage was authorized by a token issued when the editor page was rendered, and never re-checked. Someone whose access had been revoked could keep writing files indefinitely. Uploads are now authorized against current access, and the token carries a purpose and an expiry. (GHSA-h97r-8rhg-m67g)
-
Uploaded attachments were served to anyone with the URL and cached publicly for a year, regardless of whether the book was published. Attachments of unpublished books now require access to the book and are no longer publicly cacheable.
Reported by @chroxx-0000, @sps-sdp, @isacaya and @fg0x0. Full details: #463.
Full changelog: v1.2.1...v1.2.2
v1.2.1
What's Changed
- Bump nokogiri from 1.19.2 to 1.19.3 by @dependabot[bot] in #433
- Bump net-imap from 0.6.2 to 0.6.4 by @dependabot[bot] in #431
- Bump erb from 6.0.2 to 6.0.4 by @dependabot[bot] in #430
- Bump the github-actions group across 1 directory with 7 updates by @dependabot[bot] in #429
- Bump sqlite3 from 2.5.0 to 2.9.2 by @dependabot[bot] in #405
- Upgrade puma to 7.2.1 by @flavorjones in #436
- Bump net-imap from 0.6.4 to 0.6.4.1 by @dependabot[bot] in #437
- Bump concurrent-ruby from 1.3.6 to 1.3.7 by @dependabot[bot] in #441
- Bump nokogiri from 1.19.3 to 1.19.4 by @dependabot[bot] in #440
- Upgrade crass to 1.0.7 by @rosa in #442
- Bump the github-actions group across 1 directory with 8 updates by @dependabot[bot] in #438
- Bump the development-dependencies group across 1 directory with 6 updates by @dependabot[bot] in #403
- Bump the github-actions group across 1 directory with 7 updates by @dependabot[bot] in #446
- Upgrade loofah to 2.25.2 and rails-html-sanitizer to 1.7.1 by @flavorjones in #449
- Bump sqlite3 to 2.9.5 by @flavorjones in #450
- Create release script by @monorkin in #457
- Disable libvips unfuzzed operations by @flavorjones in #460
New Contributors
Full Changelog: v1.2.0...v1.2.1
v1.2.0
Security
- Delete server-side session on logout — @rosa
- Sanitize markdown output in edit history and TOC edit views (#392) — @djmb
- Sanitize search results to prevent XSS from FTS5 output (#420) — @flavorjones
Security-related dependency updates: rack, rack-session, uri, rails-html-sanitizer, nokogiri, addressable.
Features
- Markdown rendering for books and leaves — appending
.mdto any book or leaf URL renders it as inline markdown — @dhh - YAML frontmatter in markdown views — markdown output includes title, author, and URL metadata — @dhh
- HTML link tags for markdown alternate format — pages include
<link>tags pointing to the markdown version — @dhh - Use relative links for uploaded files — uploaded file URLs are now relative, improving portability — @kevinmcconnell
Other
- Add README and license — @kevinmcconnell
- Add publish-image workflow for container releases — @kevinmcconnell
- Remove redundant dev credentials and old deployment configs — @kevinmcconnell
- Update fixtures to use example domain — @kevinmcconnell