RaxBoard Core 1.9.1 released

0 Replies 24 Views
Raters
Participants
Thread Starter #1
RaxBoard Core — Core

A new release is now available on the RaxBoard Marketplace.

Version: 1.9.1 (build 20260921)
Compatibility: RaxBoard >=1.0.0

What's new
# RaxBoard 1.9.1 (build 20260921)

29 new migrations (1113–1143) over 1.9.0. No schema breaks; the upgrade is an overlay plus `migrate:run`. Recommended install order on a board: this core update first, then the language packs, add-ons and themes published alongside it.

## Security

- Structured data (JSON-LD) is emitted with HTML-safe escaping, so a title or name containing a closing script tag can no longer break out of the data block.
- Search results, snippets and suggestions never expose moderated or deleted content to visitors (see Reliability).

## Reliability

- **A page no longer dies with "null is not callable" when one boot-time lookup fails.** The request-level template helpers were registered in one block; a single failed query inside it (a table locked during an upgrade, a transient database error) left every later helper unregistered, so the very next page hit `$fmtNum` and returned a 500. Every helper now has an inert default registered up front, and the partial boot is logged instead of swallowed.
- Cookieless documents (`/sitemap.xml`, `/robots.txt`, `/favicon.ico`) no longer attempt a session regeneration, and a cached hook map that disappears mid-request is rebuilt instead of raising a warning.
- Search is filtered at the database layer by content visibility and node permission: moderated or deleted threads and posts no longer surface to visitors through search results, snippets or suggestions; the author's own pending items still show to the author. The API search endpoint applies the same scope.
- Double-submitting a thread or reply (double-click, a second POST with the same form) creates one item, not two; the form also disables itself on first submit.
- `/favicon.ico` is served by the board — the default style's favicon, then the board favicon, then the stock icon — so a page that carries no `<link rel="icon">` still shows one.

## Members and accounts

- The reserved guest-author account is no longer treated as a member anywhere: it is excluded from the member count and "newest member", top-poster and activity widgets, @mention suggestions and member pickers, trophy awards, the sitemap and the API, its profile page answers 404, and every place that linked to it now prints the plain name instead.
- Renaming a member now propagates everywhere a name is stored alongside content — thread lists, "last post by" columns, forum listings, feeds, alerts and add-on content — and a one-time repair brings already-renamed boards in line.
- Avatar upload errors are translated and shown: a rejected file (type, size, unreadable image) now explains why on the profile page instead of silently returning.
- Category links open a real category page; the ban marker is shown consistently in member lists and profiles; the "members online" page lists guest activity (and IP addresses for staff with that permission) and keeps presence rows for 30 days.

## Editor and posting

- Post preview mode and a format painter (copy/paste formatting) in the editor, with keyboard shortcuts that do not collide with browser shortcuts.
- The extra blank line inserted before an image, the poll option toggle that only worked once, the draft that was not cleared after posting, and toolbar menus clipped by the editor frame are fixed.
- Thread breadcrumbs use one shared component on forum and thread pages, so their spacing no longer differs between the two.
- Post numbering starts at #1.
- Profile tab strips never clip an extra tab (an add-on tab, a long list of tabs): the strip wraps or scrolls with a fade edge, on every theme.

## Embedded media

- **YouTube "Video player configuration error (153)" on boards that hide the Referer.** A board sending `Referrer-Policy: same-origin` stripped the referrer from the embed request, which YouTube now refuses. Every media iframe the board emits carries its own referrer policy and permissions; stored embed-site templates are patched, older posts are corrected at render time, and the admin option that hides referrers now carries a warning.

## E-mail

- Every outgoing message uses one branded template — notifications, welcome, password reset, digests, resource alerts, contact and bulk mail — with a plain-text alternative delivered as a proper multipart message.

## Admin

- Confirmation, alert and prompt dialogs use the board's language for their titles and buttons.
- Help pages: a source editor with preview, pre-fill from the base language, and a fix for the page type and description being lost on save; a Turkish board installed before its language pack receives translated help pages.
- The analytics snippet is only withheld behind a consent gate when the cookie banner is actually enabled, so a measurement ID entered without the banner works again; a warning explains the gate.
- Style customizer: dark-mode rows for every colour property, including the footer link colour; template diff page links back to the right template.
- A user-title ladder editor (levels, titles, member counts per level).

## Mobile

- Post cards, the moderation menu, the header sub-strip, notices, the reply row, pagination and footer are laid out for a 375 px screen across all shipped themes; no horizontal overflow.
- The header logo loads eagerly (it is the largest paint on most pages).

## SEO

- Error pages (404, 403, 503) are `noindex,nofollow` and emit no canonical, `og:url`, hreflang or structured data; a missing tag answers 404. Page titles set by templates now reach the layout on every theme.

Get it
View on the Marketplace

— Posted automatically by the RaxBoard Marketplace.

You must be logged in to reply.

0 quotes selected