Release 2.7.0

This commit is contained in:
ignacionelson
2026-10-06 23:12:10 -03:00
parent 2597f1a53f
commit 362e4f6917
2 changed files with 59 additions and 33 deletions
+58 -32
View File
@@ -10,45 +10,71 @@ Anything under **⚠️ Important — do these yourself** is something you have
we did. It sits at the top of a release for that reason. Older entries call the same section
**Upgrade notes**.
## Unreleased
## 2.7.0 — 6 October 2026
Four security fixes, folders you can manage over the API, and logo cropping.
### ⚠️ Important — do these yourself
Everything else in this release happens on its own, and nothing here stops the upgrade.
- **If your installation cannot send email, accounts that sign in through Google, Microsoft or
another provider can no longer set their own first password.** The link to set it now arrives by
email. Until mail works, an administrator can set the password from the person's account screen.
- **If an integration changes its own account's email address, password or two-factor
authentication through the API, it now gets a 403.** Do that from the profile screen instead.
Changing somebody else's still works as before.
**Added**
- **Folders in the API**: list, create, rename, move, delete and share them, and see where each one
sits in the tree.
- **Crop your logo** from Branding → Logo, and put the original back at any time.
- **"Import all" on the orphan files screen** adopts every match in the background and shows its
progress.
- **LDAP clients can sign in with their username** as well as their email address, once you name the
username attribute in Settings → LDAP.
**Security**
- An API token can no longer change its own owner's password, email address or two-factor
authentication, and setting somebody else's password now signs them out of the API.
- The staff screen no longer changes your own email address or password without your current
password.
- An account that signs in through a provider now gets its first password from a link sent to its
own email, not from whoever holds its browser session.
- A staff member limited to some clients now sees and revokes only their own invitations and those
into their clients' groups.
- A staff member limited to some clients no longer sees the names of folders above the ones they can
reach.
- The orphan file tool can no longer be pointed at a file that belongs to somebody.
- Creating a folder inside a public folder now needs permission to publish.
**Changed**
- **Your logo is shown larger** on the sign-in and download pages.
- **The API token screen warns you** when "Edit clients" or "Edit users" is chosen: a token with
either can sign in as the accounts it may edit.
- The Docker image no longer fills its log with passing health checks; failing ones still show.
**Fixed**
- **An API token can no longer change its own owner's password, email address or second factor,
and neither can the staff screen without your current password.** Reported by
[@simjiun](https://github.com/simjiun).
- In the client portal, changing the sort inside a folder no longer jumps back to the top, and the
chosen sort stays when you open a folder.
- Third-party libraries are updated, including fixes for published security advisories.
*Who this affected:* installations where someone holds an API token with "Manage users" and
"Edit users". Such a token could give its own owner a new password, remove their second factor,
and then sign in as them with everything they can do, including abilities the token was never
given. The same staff screen also let a signed-in administrator change their own email address
or password without the current password the profile asks for. Your own credentials are now
changed only from your profile. Setting *someone else's* password now also revokes their API
tokens. Nothing to do on upgrade.
Thanks to [@simjiun](https://github.com/simjiun), [@sbouabid-sec](https://github.com/sbouabid-sec),
[@veenone](https://github.com/veenone), [@jiits](https://github.com/jiits),
[@cookiebaker](https://github.com/cookiebaker) and
[@01110111000001](https://github.com/01110111000001) for reporting and fixing.
- **An account that signs in through Google, Microsoft or another provider now sets its first
password from a link sent to its email.** Reported by [@simjiun](https://github.com/simjiun).
### Issues closed since 2.6.0
*Who this affected:* installations with sign-in through a provider, since 2.5.0. Whoever held
such an account's browser session, for example a stolen one, could give the account a password
of their choosing and keep it after the session ended. Now "Set a password" emails a link to
the account's own address, and using it signs out every other session. Your users need working
email for this; if yours cannot send any, an administrator can still set the password for them.
The summary above is what changed. This is the paper trail, for anyone who wants to read the
original report.
- **A staff member limited to some clients now sees and revokes only their own invitations, and
those into their clients' groups.** Reported by [@sbouabid-sec](https://github.com/sbouabid-sec).
*Who this affected:* installations using client-scoped staff roles that can create clients,
since 2.5.0. The invitations screen listed every invitation, with names and email addresses,
and let such a staff member revoke any of them. Nothing to do on upgrade.
- **The orphan file tool can no longer be pointed at a file somebody owns.** Reported by
[@simjiun](https://github.com/simjiun).
*Who this affected:* every 2.x installation where a staff role can import orphan files but not
delete other people's files. Writing a file's path a little differently, for example
`./folder/file.txt`, made the tool treat a file that belongs to someone as an orphan, so it
could delete it or claim it. Nothing to do on upgrade.
- [#1798](https://github.com/projectsend/projectsend/issues/1798) — [ Feature request ] Branding : Site Name, Logo Size and Image Crop
- [#1806](https://github.com/projectsend/projectsend/issues/1806) — Sorting doesn't work with subfolders
## 2.6.0 — 25 September 2026
+1 -1
View File
@@ -234,7 +234,7 @@ return [
// A slow disk or a large source wants longer than the default 15.
'rendition_lock_wait_seconds' => env('PROJECTSEND_RENDITION_LOCK_WAIT_SECONDS'),
'version' => '2.6.0',
'version' => '2.7.0',
/*
|--------------------------------------------------------------------------