PocketBase v0.40.0

v0.40.0

v0.40.0 Release

Added 9
  • Add quotes around the default Content-Disposition serving filename when a custom name with special characters is provided
  • Add Cross-Origin-Opener-Policy:same-origin to default security response headers
  • Add Record.GetInt64(field) helper method
  • Add Store.Keys() method that returns a slice with all store keys
  • Add DELETE /api/logs endpoint and UI control to delete all logs without changing the maxDays retention setting
  • Add new log settings option to limit the max Log.Data size saved in the database with truncation at ~16KB and max 8k characters for the log message
Changed 4
  • Propagate console command errors and recovered panics to app.Start() so that the program exits with non-zero code while still ensuring app.OnTerminate hook was triggered
  • Optimize backups to no longer transaction lock the database during backup generation
  • Update modernc.org/sqlite to 1.57.0 and register by default the new _defensive=1 DSN query parameter to enable SQLite's defensive mode
  • Bump minimum Go version to 1.27.0 and migrate to the new encoding/json/v2 package

From PocketBase

To update the prebuilt executable you can run ./pocketbase update.

  • Propagate console command errors and recovered panics to app.Start() so that the program can exit with non-zero code while still ensuring that app.OnTerminate hook was triggered (responsible for the app graceful shutdown handling). ⚠️ Note that this could be a slight breaking change in case you are chaining PocketBase commands and relied on the previous 0 exit status for Command.RunE returned errors. Or in other words, if you have ./pocketbase invalid && someothercommand and previously relied that someothercommand will be always executed then this is no longer the case and you'll have to adjust it or replace && with ;.

  • Added quotes around the default Content-Disposition serving filename in case custom name with special characters is provided.

  • Added Cross-Origin-Opener-Policy:same-origin to the default security response headers. This is an extra precaution to prevent tab-nabbing in case custom UI plugins use target="_blank" without rel="noopener".

  • Added Record.GetInt64(field) helper (note that the serializable max safe integer of the number field is ~2^53-1).

  • Added Store.Keys() method that returns a slice with all of the store keys.

  • Added new DELETE /api/logs endpoint and UI control to delete all logs without changing the maxDays retention setting.

  • Added new log settings option to limit the max Log.Data size that will be saved in the database (default to ~16KB). This is an extra precaution for the cases when logging user supplied data without validating it beforehand. If the resulting Log.Data json is above the limit, it is truncated to the last valid decoded character and an extra "__pb_truncated__":true log data entry will be added.` Additionally, for just in case the log message is also truncated at max 8k characters.

  • Added new filesystem low-level helper methods:

    • filesystem.NewWriter(key, opts) to allow direct file create from an io.Reader value.
    • filesystem.OnNewWriter() hook to allow listening for new/to-be-created files (it is not exposed in core.App instance for now to avoid introducing breaking changes).
    • filesystem.OnDelete() hook to allow listening for deleted files (it is not exposed in core.App instance for now to avoid introducing breaking changes).
  • Optimized backups to no longer transaction lock the database during backup generation (#7799).

  • Updated modernc.org/sqlite to 1.57.0 and registered by default the new _defensive=1 DSN query parameter to enable SQLite's defensive mode.

  • Bumped the min Go version to 1.27.0 and migrated to the new encoding/json/v2 package. ⚠️ Please note that Go 1.27.0 retrofitted encoding/json to use the v2 package under the hood but unfortunately is not fully backward compatible. I recommend to not push blindly an update on production and to test your PocketBase application first locally to see if everything works correctly.

View original

Upgraded? How did it go?

Discussion