FreshRSS 1.26.2

1.26.2

FreshRSS 1.26.2

Added 4
  • Implement JSON string concatenation with & operator
  • Support multiple JSON fragments in HTML+XPath+JSON mode
  • New size option for the Mark as read button
  • New JavaScript event to detect context loaded
Fixed 6
  • Fix escaping of tag search
  • Fix CLI parsing of Boolean flags
  • Fix API for labels with slash
  • Fix support for feeds with XML preamble + DTD
  • Fix file serving for symlinked extensions
  • Catch extension exceptions in override
Security 10
  • Disallow <iframe srcdoc="">
  • Disallow <button formaction="">
  • Improve favicons hash to avoid favicon pollution
  • Add Content-Security-Policy HTTP headers to favicons
  • Web scraping forbid security HTTP headers in cURL
  • Add HTTP headers Referrer-Policy: same-origin

This is a security-focussed release for FreshRSS 1.26.x, addressing several CVEs (thanks @Inverle) 🛡

A few highlights ✨:

  • Implement JSON string concatenation with & operator
  • Support multiple JSON fragments in HTML+XPath+JSON mode (e.g. JSON-LD)
  • Multiple security fixes with CVEs
  • Bug fixes

Notes ℹ:

  • Favicons will be reconstructed automatically when feeds gets refreshed. After that, you may need to refresh your Web browser as well.

This release has been made by @Alkarex, @Frenzie, @hkcomori, @loviuz, @math-GH and newcomers @dezponia, @glyn, @Inverle, @Machou, @mikropsoft

Full changelog:

View original

Upgraded? How did it go?

Discussion