Update ghcr.io/ancsemi/haven Docker tag in stack haven from 4.11.0 to v4.12.0 #528
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/ghcr.io-ancsemi-haven-4.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
4.11.0→4.12.0Release Notes
ancsemi/Haven (ghcr.io/ancsemi/haven)
v4.12.0Compare Source
A security release: please update soon. A full review of the server and
the web app closed holes that let someone with only a password skip
two-factor, let any member delete other people's files or read channels
they were kept out of, and sent the Discord bridge's bot token to every
signed-in browser. If you use the Discord bridge, reset the bot's token
after updating (see Security below). Alongside it: pictures and files
inside forum posts, tags on forum pictures, roles and channels across the
Discord bridge, and a too-long message no longer lost. Nothing to run by
hand.
Security
A full security review of the server and the web app. Update soon: several
of these let someone signed in, or someone with only a password, do far
more than they should. If you use the Discord bridge, reset the bot's token
in the Discord Developer Portal after updating and paste the new one into
Settings, since earlier versions sent it to every signed-in browser.
out between the password and the code was accepted as a login in a few
places, including the forced password change and turning two-factor off,
and admin recovery asked for no code at all. Only a real session counts
as a login now, admin recovery asks for the code, and wrong codes are
limited per account as well as per address.
every signed-in user; it now goes to nobody. GIF service keys, the TURN
password, the CAPTCHA secret, the invite code and the registration token
went to everyone whenever an admin changed them, and into the audit log;
they go to admins only now, and the audit log records only that they
changed.
network, through a redirect, an IPv6 address or an unusual spelling of
a local address. Every step of a fetch is checked now, and the connection
goes to the address that was checked. Previews also stop reading a page
after 256 KB.
attachments) by naming them in a message of their own and deleting it.
Deleting a message now only removes files its author uploaded as
attachments that nothing else uses.
opens as a plain image now, and uploads other than pictures, audio and
video are served in a form a browser will not run as script.
call, went to everyone through the voice counts; channels that need a
role could be read through search, media, threads and pins, and entered
live, by members without the role.
roles, role menus, permission thresholds and a channel's default role only
work on people and roles ranked below you. Moderators could attach bots
to private channels and DMs, move messages into channels they could not
post in, and delete sub-channels with only the create-channel permission.
The HTTP moderation routes skipped the rank checks the app makes.
everywhere. Channel moderators could mute anyone ranked below them across
the whole server. Unmuting follows the same rule as unbanning.
channel's required roles, the guest switch and the room limit.
@everyone and role pings need permission, and Discord users could ping
@everyone or a Haven role by typing it. Polls are refused in DMs (they are
not encrypted), GIFs in DMs are encrypted now, and scheduled messages are
checked again when they go out.
whole file is on disk, so one upload cannot fill the server's disk.
tooltips escape names, an invisible user shows as offline on their
profile, an admin password reset closes the person's open sessions,
banned accounts get no voice relay credentials, push subscriptions only
go to public addresses, the public high-score list drops account ids,
forum titles get automod, the slow-mode exception for attachments cannot
be claimed by any message, the active sessions list names devices again,
and a translations check on GitHub no longer runs file names as shell
text. Four libraries with published fixes were updated (adm-zip, express,
body-parser, qs).
Added
Edit post have an Add a picture or file button, and a picture pasted or
dropped into the body uploads too. Each one goes in where the cursor is,
on a line of its own, so a guide can be text, a picture, more text. The
topic shows them in place; before, a topic sent as text plus a picture
showed the picture's link instead of the picture.
works in forum channels, a topic sent as text with pictures keeps their
tags, and Edit tags is on the right-click menu of a topic's picture, on
its card, in the topic itself, and on a reply's picture. The tags show
under the topic and under each reply.
picture, and right-clicking the picture gets the image menu, so deleting
a topic was hard to find.
mentioned on Discord used to arrive in Haven as a string of digits; it
arrives as @Role and #channel now, and a Discord channel paired with a
Haven one shows as a link to it. With Allow pings on, an @Role pings both
sides together: from Discord it lights up the Haven role of the same
name, and from Haven it pings the Discord role, as long as that role is
one anybody on Discord may mention. A #channel from Haven reaches Discord
as a link too.
Fixed
the message box now so it can be trimmed. The usual cause was an
encrypted DM: the server measured it after encryption, which makes it
longer, so a DM well under the limit could be refused. The server allows
for what encryption adds now.
theme is stored as
file:<name>.theme.css, and a name given without that prefixwas applied as an unknown built-in: the page loaded no stylesheet and nothing
anywhere reported a problem. A file theme is now served in the form the client
understands however it was named, and a name that no longer resolves to a
published theme no longer reaches a client at all.
Closing a thread or topic, or switching channels, now stops it.
(#5688). It goes back to the topic list now.
whole thread panel takes the drop now, not only the reply box.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.