3 hours ago
etherpad

v3.3.8

3.3.8

3.3.8 is a security release. It closes an HTTP API privilege escalation for instances using the built-in OIDC provider with API clients (GHSA-38vj-95q4-gwvx).

Security

  • HTTP API — client_credentials tokens are identified by a signed grant marker (GHSA-38vj-95q4-gwvx). The API decided whether a bearer JWT came from the OAuth2 client_credentials grant by checking whether its sub claim equalled a configured client_id, and client_credentials tokens skip the admin === true claim check. A non-admin user whose account name collided with a configured client ID could therefore use an ordinary login token to get admin access to the HTTP API. This is a variant of GHSA-qfmh-fph3-mw8q. The provider now signs an etherpad_grant: "client_credentials" marker into client_credentials access tokens, and extraParams cannot override it. The API trusts that marker instead of comparing sub to client IDs. Upgrade note: client_credentials tokens issued before the upgrade don't carry the marker and are refused with 401 until they are re-issued. These tokens are short-lived. Reported by Yves Soete of Blacksight LLC (@yssoe).

Notable fixes

  • OIDC — numeric and boolean admin passwords work again (#8263, #8327). The settings loader coerces environment-variable values, so ADMIN_PASSWORD=123456 (for example via settings.json.docker) arrives as the number 123456. The 3.3.6 login check (GHSA-62cj-9j72-mfrh) only accepted string passwords, so these admins could no longer log in. Finite numbers and booleans are now compared as strings. Missing, empty, NaN and non-scalar values are still refused.
  • Settings — dropdowns open under prefers-reduced-motion (#8290, #8328). With reduced motion enabled, the settings popup kept transform: scale(1). That made the popup the containing block for the dropdown list, so the font and language lists rendered out of view. The popup now uses transform: none. Thanks to @kfogel.
5 hours ago
virtual

@tanstack/svelte-virtual@3.13.41

Patch Changes

  • Updated dependencies [28a2174, 92c697f]:
    • @tanstack/virtual-core@3.19.0
5 hours ago
virtual

@tanstack/react-virtual@3.14.15

Patch Changes

  • Updated dependencies [28a2174, 92c697f]:
    • @tanstack/virtual-core@3.19.0
5 hours ago
virtual

@tanstack/vue-virtual@3.13.41

Patch Changes

  • Updated dependencies [28a2174, 92c697f]:
    • @tanstack/virtual-core@3.19.0
5 hours ago
virtual

@tanstack/lit-virtual@3.14.4

Patch Changes

  • Updated dependencies [28a2174, 92c697f]:
    • @tanstack/virtual-core@3.19.0
5 hours ago
virtual

@tanstack/marko-virtual@3.16.1

Patch Changes

  • Updated dependencies [28a2174, 92c697f]:
    • @tanstack/virtual-core@3.19.0
5 hours ago
virtual

@tanstack/angular-virtual@6.1.1

Patch Changes

  • Updated dependencies [28a2174, 92c697f]:
    • @tanstack/virtual-core@3.19.0
5 hours ago
virtual

@tanstack/solid-virtual@3.13.42

Patch Changes

  • Updated dependencies [28a2174, 92c697f]:
    • @tanstack/virtual-core@3.19.0
5 hours ago
virtual

@tanstack/virtual-core@3.19.0

Minor Changes

  • #1302 92c697f - fix(virtual-core): keep lanes aligned after changing lanes with measureElement (#1036)
    • overscan now counts whole rows when lanes > 1, so every lane renders (and measures) the same number of extra items. This renders more items than before: lanes: 4, overscan: 2 now adds 8 items on each side instead of 2. Range gains an optional lanes field that defaultRangeExtractor reads; a custom rangeExtractor gets row overscan only if it delegates to defaultRangeExtractor.
    • A ResizeObserver callback now measures all of its entries before notifying, so a synchronous re-render can no longer unmount part of a row before it is measured.

Patch Changes

  • #1305 28a2174 - fix(virtual-core): don't replay iOS-deferred size corrections after an in-flight scrollToIndex lands
6 hours ago
react-highlight-words

0.21.1

The component's behavior is unchanged, but the package is now built with Vite instead of webpack. Check the packaging changes below if you use an older bundler or runtime, or load the UMD build.

  • Add TypeScript type definitions (dist/react-highlight-words.d.ts), including exported HighlighterProps, HighlightTagProps, UnhighlightTagProps, Chunk and FindChunksOptions types.
  • Add an ES module build (dist/react-highlight-words.js), exposed through the module field.
  • Move the CommonJS entry point from dist/main.js to dist/react-highlight-words.cjs. require("react-highlight-words") still returns the component directly.
  • Target modern JavaScript (ES2018+: object spread, destructuring defaults, const/let) instead of ES5. Environments that can't parse that syntax need to transpile the package.
  • Stop bundling highlight-words-core into the build; it is installed as a regular dependency (^1.2.0).
  • Lowercase the keys of an object highlightClassName once per render instead of once per match (when caseSensitive is false).
  • Remove the UMD build (dist/main.umd.js).
  • Remove the memoize-one dependency.