Update ghcr.io/ancsemi/haven Docker tag in stack haven from 4.11.0 to v4.12.0 #528

Merged
Kevin merged 1 commit from renovate/ghcr.io-ancsemi-haven-4.x into main 2026-09-24 07:20:35 -04:00
Collaborator

This PR contains the following updates:

Package Update Change
ghcr.io/ancsemi/haven minor 4.11.0 → 4.12.0

Release Notes

ancsemi/Haven (ghcr.io/ancsemi/haven)

v4.12.0

Compare Source

A security release: please update soon. A full review of the server and
the web app closed holes that let someone with only a password skip
two-factor, let any member delete other people's files or read channels
they were kept out of, and sent the Discord bridge's bot token to every
signed-in browser. If you use the Discord bridge, reset the bot's token
after updating (see Security below). Alongside it: pictures and files
inside forum posts, tags on forum pictures, roles and channels across the
Discord bridge, and a too-long message no longer lost. Nothing to run by
hand.

Security

A full security review of the server and the web app. Update soon: several
of these let someone signed in, or someone with only a password, do far
more than they should. If you use the Discord bridge, reset the bot's token
in the Discord Developer Portal after updating and paste the new one into
Settings, since earlier versions sent it to every signed-in browser.

  • Two-factor could be skipped with the password alone. The token handed
    out between the password and the code was accepted as a login in a few
    places, including the forced password change and turning two-factor off,
    and admin recovery asked for no code at all. Only a real session counts
    as a login now, admin recovery asks for the code, and wrong codes are
    limited per account as well as per address.
  • Secrets reached people they should not. The Discord bot token went to
    every signed-in user; it now goes to nobody. GIF service keys, the TURN
    password, the CAPTCHA secret, the invite code and the registration token
    went to everyone whenever an admin changed them, and into the audit log;
    they go to admins only now, and the audit log records only that they
    changed.
  • Link previews and the image proxy could be pointed at the server's own
    network
    , through a redirect, an IPv6 address or an unusual spelling of
    a local address. Every step of a fetch is checked now, and the connection
    goes to the address that was checked. Previews also stop reading a page
    after 256 KB.
  • Anyone could permanently delete other people's files (avatars, emoji,
    attachments) by naming them in a message of their own and deleting it.
    Deleting a message now only removes files its author uploaded as
    attachments that nothing else uses.
  • An encrypted DM picture could run code when opened in a new tab. It
    opens as a plain image now, and uploads other than pictures, audio and
    video are served in a form a browser will not run as script.
  • Private channels leaked. Their join codes, and who was in which DM
    call, went to everyone through the voice counts; channels that need a
    role could be read through search, media, threads and pins, and entered
    live, by members without the role.
  • Permissions followed rank in more places. Giving, taking and editing
    roles, role menus, permission thresholds and a channel's default role only
    work on people and roles ranked below you. Moderators could attach bots
    to private channels and DMs, move messages into channels they could not
    post in, and delete sub-channels with only the create-channel permission.
    The HTTP moderation routes skipped the rank checks the app makes.
  • Muting now needs the mute permission server-wide, since a mute applies
    everywhere. Channel moderators could mute anyone ranked below them across
    the whole server. Unmuting follows the same rule as unbanning.
  • Voice: rejoining after a reconnect skipped the voice permission, the
    channel's required roles, the guest switch and the room limit.
  • Pings: threads, polls and scheduled messages skipped the rule that
    @​everyone and role pings need permission, and Discord users could ping
    @​everyone or a Haven role by typing it. Polls are refused in DMs (they are
    not encrypted), GIFs in DMs are encrypted now, and scheduled messages are
    checked again when they go out.
  • Uploads stop at your size cap while they arrive, instead of after the
    whole file is on disk, so one upload cannot fill the server's disk.
  • Smaller fixes: the single sign-on page escapes what it prints, reaction
    tooltips escape names, an invisible user shows as offline on their
    profile, an admin password reset closes the person's open sessions,
    banned accounts get no voice relay credentials, push subscriptions only
    go to public addresses, the public high-score list drops account ids,
    forum titles get automod, the slow-mode exception for attachments cannot
    be claimed by any message, the active sessions list names devices again,
    and a translations check on GitHub no longer runs file names as shell
    text. Four libraries with published fixes were updated (adm-zip, express,
    body-parser, qs).
Added
  • Pictures and files inside forum posts (#​5689, #​5690). New Post and
    Edit post have an Add a picture or file button, and a picture pasted or
    dropped into the body uploads too. Each one goes in where the cursor is,
    on a line of its own, so a guide can be text, a picture, more text. The
    topic shows them in place; before, a topic sent as text plus a picture
    showed the picture's link instead of the picture.
  • Attachment tags in forums (#​5682). The tag bar under the message box
    works in forum channels, a topic sent as text with pictures keeps their
    tags, and Edit tags is on the right-click menu of a topic's picture, on
    its card, in the topic itself, and on a reply's picture. The tags show
    under the topic and under each reply.
  • Delete topic in Edit post (#​5690). A gallery card is nearly all
    picture, and right-clicking the picture gets the image menu, so deleting
    a topic was hard to find.
  • Roles and channels across the Discord bridge. A role or channel
    mentioned on Discord used to arrive in Haven as a string of digits; it
    arrives as @​Role and #channel now, and a Discord channel paired with a
    Haven one shows as a link to it. With Allow pings on, an @​Role pings both
    sides together: from Discord it lights up the Haven role of the same
    name, and from Haven it pings the Discord role, as long as that role is
    one anybody on Discord may mention. A #channel from Haven reaches Discord
    as a link too.
Fixed
  • A message refused as too long was lost (#​5691). It comes back into
    the message box now so it can be trimmed. The usual cause was an
    encrypted DM: the server measured it after encryption, which makes it
    longer, so a DM well under the limit could be refused. The server allows
    for what encryption adds now.
  • A custom theme set as the server default could load no theme at all. A file
    theme is stored as file:<name>.theme.css, and a name given without that prefix
    was applied as an unknown built-in: the page loaded no stylesheet and nothing
    anywhere reported a problem. A file theme is now served in the form the client
    understands however it was named, and a name that no longer resolves to a
    published theme no longer reaches a client at all.
  • A video in a forum topic kept playing after leaving it (#​5690).
    Closing a thread or topic, or switching channels, now stops it.
  • Clicking the forum you are in did nothing while a topic was open
    (#​5688).
    It goes back to the topic list now.
  • Dropping a file on a forum topic's replies did nothing (#​5684). The
    whole thread panel takes the drop now, not only the reply box.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ghcr.io/ancsemi/haven](https://github.com/ancsemi/Haven) | minor | `4.11.0` → `4.12.0` | --- ### Release Notes <details> <summary>ancsemi/Haven (ghcr.io/ancsemi/haven)</summary> ### [`v4.12.0`](https://github.com/ancsemi/Haven/blob/HEAD/CHANGELOG.md#4120---2026-09-23) [Compare Source](https://github.com/ancsemi/Haven/compare/v4.11.0...v4.12.0) A security release: please update soon. A full review of the server and the web app closed holes that let someone with only a password skip two-factor, let any member delete other people's files or read channels they were kept out of, and sent the Discord bridge's bot token to every signed-in browser. If you use the Discord bridge, reset the bot's token after updating (see Security below). Alongside it: pictures and files inside forum posts, tags on forum pictures, roles and channels across the Discord bridge, and a too-long message no longer lost. Nothing to run by hand. ##### Security A full security review of the server and the web app. Update soon: several of these let someone signed in, or someone with only a password, do far more than they should. If you use the Discord bridge, reset the bot's token in the Discord Developer Portal after updating and paste the new one into Settings, since earlier versions sent it to every signed-in browser. - **Two-factor could be skipped with the password alone.** The token handed out between the password and the code was accepted as a login in a few places, including the forced password change and turning two-factor off, and admin recovery asked for no code at all. Only a real session counts as a login now, admin recovery asks for the code, and wrong codes are limited per account as well as per address. - **Secrets reached people they should not.** The Discord bot token went to every signed-in user; it now goes to nobody. GIF service keys, the TURN password, the CAPTCHA secret, the invite code and the registration token went to everyone whenever an admin changed them, and into the audit log; they go to admins only now, and the audit log records only that they changed. - **Link previews and the image proxy could be pointed at the server's own network**, through a redirect, an IPv6 address or an unusual spelling of a local address. Every step of a fetch is checked now, and the connection goes to the address that was checked. Previews also stop reading a page after 256 KB. - **Anyone could permanently delete other people's files** (avatars, emoji, attachments) by naming them in a message of their own and deleting it. Deleting a message now only removes files its author uploaded as attachments that nothing else uses. - **An encrypted DM picture could run code** when opened in a new tab. It opens as a plain image now, and uploads other than pictures, audio and video are served in a form a browser will not run as script. - **Private channels leaked.** Their join codes, and who was in which DM call, went to everyone through the voice counts; channels that need a role could be read through search, media, threads and pins, and entered live, by members without the role. - **Permissions followed rank in more places.** Giving, taking and editing roles, role menus, permission thresholds and a channel's default role only work on people and roles ranked below you. Moderators could attach bots to private channels and DMs, move messages into channels they could not post in, and delete sub-channels with only the create-channel permission. The HTTP moderation routes skipped the rank checks the app makes. - **Muting now needs the mute permission server-wide**, since a mute applies everywhere. Channel moderators could mute anyone ranked below them across the whole server. Unmuting follows the same rule as unbanning. - **Voice**: rejoining after a reconnect skipped the voice permission, the channel's required roles, the guest switch and the room limit. - **Pings**: threads, polls and scheduled messages skipped the rule that [@&#8203;everyone](https://github.com/everyone) and role pings need permission, and Discord users could ping [@&#8203;everyone](https://github.com/everyone) or a Haven role by typing it. Polls are refused in DMs (they are not encrypted), GIFs in DMs are encrypted now, and scheduled messages are checked again when they go out. - **Uploads stop at your size cap while they arrive**, instead of after the whole file is on disk, so one upload cannot fill the server's disk. - **Smaller fixes**: the single sign-on page escapes what it prints, reaction tooltips escape names, an invisible user shows as offline on their profile, an admin password reset closes the person's open sessions, banned accounts get no voice relay credentials, push subscriptions only go to public addresses, the public high-score list drops account ids, forum titles get automod, the slow-mode exception for attachments cannot be claimed by any message, the active sessions list names devices again, and a translations check on GitHub no longer runs file names as shell text. Four libraries with published fixes were updated (adm-zip, express, body-parser, qs). ##### Added - **Pictures and files inside forum posts ([#&#8203;5689](https://github.com/ancsemi/Haven/issues/5689), [#&#8203;5690](https://github.com/ancsemi/Haven/issues/5690)).** New Post and Edit post have an Add a picture or file button, and a picture pasted or dropped into the body uploads too. Each one goes in where the cursor is, on a line of its own, so a guide can be text, a picture, more text. The topic shows them in place; before, a topic sent as text plus a picture showed the picture's link instead of the picture. - **Attachment tags in forums ([#&#8203;5682](https://github.com/ancsemi/Haven/issues/5682)).** The tag bar under the message box works in forum channels, a topic sent as text with pictures keeps their tags, and Edit tags is on the right-click menu of a topic's picture, on its card, in the topic itself, and on a reply's picture. The tags show under the topic and under each reply. - **Delete topic in Edit post ([#&#8203;5690](https://github.com/ancsemi/Haven/issues/5690)).** A gallery card is nearly all picture, and right-clicking the picture gets the image menu, so deleting a topic was hard to find. - **Roles and channels across the Discord bridge.** A role or channel mentioned on Discord used to arrive in Haven as a string of digits; it arrives as [@&#8203;Role](https://github.com/Role) and #channel now, and a Discord channel paired with a Haven one shows as a link to it. With Allow pings on, an [@&#8203;Role](https://github.com/Role) pings both sides together: from Discord it lights up the Haven role of the same name, and from Haven it pings the Discord role, as long as that role is one anybody on Discord may mention. A #channel from Haven reaches Discord as a link too. ##### Fixed - **A message refused as too long was lost ([#&#8203;5691](https://github.com/ancsemi/Haven/issues/5691)).** It comes back into the message box now so it can be trimmed. The usual cause was an encrypted DM: the server measured it after encryption, which makes it longer, so a DM well under the limit could be refused. The server allows for what encryption adds now. - **A custom theme set as the server default could load no theme at all.** A file theme is stored as `file:<name>.theme.css`, and a name given without that prefix was applied as an unknown built-in: the page loaded no stylesheet and nothing anywhere reported a problem. A file theme is now served in the form the client understands however it was named, and a name that no longer resolves to a published theme no longer reaches a client at all. - **A video in a forum topic kept playing after leaving it ([#&#8203;5690](https://github.com/ancsemi/Haven/issues/5690)).** Closing a thread or topic, or switching channels, now stops it. - **Clicking the forum you are in did nothing while a topic was open ([#&#8203;5688](https://github.com/ancsemi/Haven/issues/5688)).** It goes back to the topic list now. - **Dropping a file on a forum topic's replies did nothing ([#&#8203;5684](https://github.com/ancsemi/Haven/issues/5684)).** The whole thread panel takes the drop now, not only the reply box. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMjMuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEyMy4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtaW5vciIsInJlbm92YXRlIl19-->
renovate-bot scheduled this pull request to auto merge when all checks succeed 2026-09-24 01:02:30 -04:00
Kevin merged commit d5ab714f87 into main 2026-09-24 07:20:35 -04:00
Sign in to join this conversation.
No reviewers
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Kevin/docker-l2!528
No description provided.