v3.3.8
3.3.8 is a security release. It closes an HTTP API privilege escalation for instances using the built-in OIDC provider with API clients (GHSA-38vj-95q4-gwvx).
- HTTP API — client_credentials tokens are identified by a signed grant marker (GHSA-38vj-95q4-gwvx). The API decided whether a bearer JWT came from the OAuth2
client_credentialsgrant by checking whether itssubclaim equalled a configuredclient_id, andclient_credentialstokens skip theadmin === trueclaim check. A non-admin user whose account name collided with a configured client ID could therefore use an ordinary login token to get admin access to the HTTP API. This is a variant of GHSA-qfmh-fph3-mw8q. The provider now signs anetherpad_grant: "client_credentials"marker into client_credentials access tokens, andextraParamscannot override it. The API trusts that marker instead of comparingsubto client IDs. Upgrade note: client_credentials tokens issued before the upgrade don't carry the marker and are refused with 401 until they are re-issued. These tokens are short-lived. Reported by Yves Soete of Blacksight LLC (@yssoe).
- OIDC — numeric and boolean admin passwords work again (#8263, #8327). The settings loader coerces environment-variable values, so
ADMIN_PASSWORD=123456(for example viasettings.json.docker) arrives as the number123456. The 3.3.6 login check (GHSA-62cj-9j72-mfrh) only accepted string passwords, so these admins could no longer log in. Finite numbers and booleans are now compared as strings. Missing, empty, NaN and non-scalar values are still refused. - Settings — dropdowns open under
prefers-reduced-motion(#8290, #8328). With reduced motion enabled, the settings popup kepttransform: scale(1). That made the popup the containing block for the dropdown list, so the font and language lists rendered out of view. The popup now usestransform: none. Thanks to @kfogel.
@tanstack/virtual-core@3.19.0
- #1302
92c697f- fix(virtual-core): keep lanes aligned after changinglaneswithmeasureElement(#1036)overscannow counts whole rows whenlanes > 1, so every lane renders (and measures) the same number of extra items. This renders more items than before:lanes: 4, overscan: 2now adds 8 items on each side instead of 2.Rangegains an optionallanesfield thatdefaultRangeExtractorreads; a customrangeExtractorgets row overscan only if it delegates todefaultRangeExtractor.- A ResizeObserver callback now measures all of its entries before notifying, so a synchronous re-render can no longer unmount part of a row before it is measured.
0.21.1
The component's behavior is unchanged, but the package is now built with Vite instead of webpack. Check the packaging changes below if you use an older bundler or runtime, or load the UMD build.
- Add TypeScript type definitions (
dist/react-highlight-words.d.ts), including exportedHighlighterProps,HighlightTagProps,UnhighlightTagProps,ChunkandFindChunksOptionstypes. - Add an ES module build (
dist/react-highlight-words.js), exposed through themodulefield. - Move the CommonJS entry point from
dist/main.jstodist/react-highlight-words.cjs.require("react-highlight-words")still returns the component directly. - Target modern JavaScript (ES2018+: object spread, destructuring defaults,
const/let) instead of ES5. Environments that can't parse that syntax need to transpile the package. - Stop bundling
highlight-words-coreinto the build; it is installed as a regular dependency (^1.2.0). - Lowercase the keys of an object
highlightClassNameonce per render instead of once per match (whencaseSensitiveisfalse). - Remove the UMD build (
dist/main.umd.js). - Remove the
memoize-onedependency.