Autor del tema
#1
RaxBoard Core — Core
A new release is now available on the RaxBoard Marketplace.
Version: 1.9.3 (build 20260924)
Compatibility: RaxBoard >=1.0.0
What's new
# RaxBoard 1.9.3 (build 20260924)
22 new migrations (1147–1168) over 1.9.2. No schema breaks; the upgrade is an overlay plus `migrate:run`. Recommended install order on a board: this core update first, then the add-ons and themes published alongside it.
## RaxBoard Analytics — new
- A new top-level admin panel: **traffic** (organic / direct / referral / bot, top pages, a page-view chart with date-range and comparison), **forum activity** (threads, posts, new members per day), **members** (who's online, active hours) and **bots**, plus CSV export for each. Built to add effectively no per-request cost: visits are appended to a local file during the response that already ran, and a scheduled background job turns that into the numbers the panel shows — nothing runs synchronously on a page a visitor is looking at. No cookies are set for visitor tracking; a daily-rotating identity is derived instead.
- Ships disabled by nothing and is on by default after the upgrade; `Analytics → Settings` has the on/off switch, exclusions and a data-reset action. See `Analytics → Settings` for retention and privacy controls, including the board's existing "forget this member" flow, which now also clears their analytics history.
## Security
- **Admin panel: closed a stored XSS in the Marketplace screen.** An update banner assembled its text as raw HTML instead of a text node — a name coming from the raxboard.com catalog, or from an installed language pack's own phrase text, could run script in an admin's browser. Neither is data the admin panel should ever have trusted outright. Both the banner and the equivalent line on each catalog card are fixed.
- **Sign-in / registration: a spam-catching field could lock members out instead of bots.** Some phone password managers fill in every field they can find, including one meant to stay empty; the board then read that autofill as a bot and refused the member's own login or registration ("Invalid request"). The field no longer accepts autofill.
## Admin: Marketplace
- The catalog card and the update/install dialog were rebuilt: keyboard users can now open, tab through and close them correctly (a stray Escape used to close two dialogs at once); an "All" tab lists every add-on, theme and language pack together; bulk "Update all" shows real per-item progress and retries only the ones that failed; a product's past versions and their release notes are one click away; a product you already installed outside the marketplace (uploaded as a zip, installed from the CLI, or carried over by a migration) is now recognised as installed instead of being offered for a fresh "Install".
- Fixed: the sort dropdown's field width collapsing to a sliver on some admin themes; a broken product image leaving a broken-image icon instead of a placeholder; the "installed/update available" check timing out slowly for paid, not-yet-owned add-ons.
## Forums
- **A forum's sub-forums could read "No messages yet." even when they had recent posts.** The sub-forum row was computing its own counts instead of using the ones the page already had, and lost the last-post details along the way. Fixed on every forum listing.
- The small coloured prefix chip on a forum's "last post" line was never showing — it was reading a field the board has never actually sent. It now shows correctly, matching the chip everywhere else it already appeared.
## Help & legal pages, trophies
- Help and legal pages (rules, privacy, terms, …) now pick up a newly installed or updated language pack's translations on their own; previously only a board that already had that language installed when its help pages were first seeded got the translation.
- Cleaned up leftover half-translated rows this left behind on some boards, and the equivalent leftover rows for trophy names/descriptions after a language pack import.
## Admin login, and other fixes
- Fixed a page-breaking script error that could appear on `/admin/login` after certain theme/script updates.
- A handful of interface strings (sign-in, sign-up, "mark forums read", forum watch and others) that were silently falling back to their raw, untranslated key instead of readable English text when a phrase row was missing now show the intended text instead.
- A rendering bug from an earlier migration left a small number of pages (a conversation's "loading…" text, two spots each on a thread and a profile page, on a few themes) printing a literal, unreadable code fragment instead of running it. Fixed at the source and for every page it had already reached.
## Notes for theme and add-on authors
- `RAXBOARD_ANALYTICS_SPEC.md` documents the Analytics data model and the read API for anyone building a custom reporting view. No theme-facing markup changed.
Get it
View on the Marketplace
— Posted automatically by the RaxBoard Marketplace.
A new release is now available on the RaxBoard Marketplace.
Version: 1.9.3 (build 20260924)
Compatibility: RaxBoard >=1.0.0
What's new
# RaxBoard 1.9.3 (build 20260924)
22 new migrations (1147–1168) over 1.9.2. No schema breaks; the upgrade is an overlay plus `migrate:run`. Recommended install order on a board: this core update first, then the add-ons and themes published alongside it.
## RaxBoard Analytics — new
- A new top-level admin panel: **traffic** (organic / direct / referral / bot, top pages, a page-view chart with date-range and comparison), **forum activity** (threads, posts, new members per day), **members** (who's online, active hours) and **bots**, plus CSV export for each. Built to add effectively no per-request cost: visits are appended to a local file during the response that already ran, and a scheduled background job turns that into the numbers the panel shows — nothing runs synchronously on a page a visitor is looking at. No cookies are set for visitor tracking; a daily-rotating identity is derived instead.
- Ships disabled by nothing and is on by default after the upgrade; `Analytics → Settings` has the on/off switch, exclusions and a data-reset action. See `Analytics → Settings` for retention and privacy controls, including the board's existing "forget this member" flow, which now also clears their analytics history.
## Security
- **Admin panel: closed a stored XSS in the Marketplace screen.** An update banner assembled its text as raw HTML instead of a text node — a name coming from the raxboard.com catalog, or from an installed language pack's own phrase text, could run script in an admin's browser. Neither is data the admin panel should ever have trusted outright. Both the banner and the equivalent line on each catalog card are fixed.
- **Sign-in / registration: a spam-catching field could lock members out instead of bots.** Some phone password managers fill in every field they can find, including one meant to stay empty; the board then read that autofill as a bot and refused the member's own login or registration ("Invalid request"). The field no longer accepts autofill.
## Admin: Marketplace
- The catalog card and the update/install dialog were rebuilt: keyboard users can now open, tab through and close them correctly (a stray Escape used to close two dialogs at once); an "All" tab lists every add-on, theme and language pack together; bulk "Update all" shows real per-item progress and retries only the ones that failed; a product's past versions and their release notes are one click away; a product you already installed outside the marketplace (uploaded as a zip, installed from the CLI, or carried over by a migration) is now recognised as installed instead of being offered for a fresh "Install".
- Fixed: the sort dropdown's field width collapsing to a sliver on some admin themes; a broken product image leaving a broken-image icon instead of a placeholder; the "installed/update available" check timing out slowly for paid, not-yet-owned add-ons.
## Forums
- **A forum's sub-forums could read "No messages yet." even when they had recent posts.** The sub-forum row was computing its own counts instead of using the ones the page already had, and lost the last-post details along the way. Fixed on every forum listing.
- The small coloured prefix chip on a forum's "last post" line was never showing — it was reading a field the board has never actually sent. It now shows correctly, matching the chip everywhere else it already appeared.
## Help & legal pages, trophies
- Help and legal pages (rules, privacy, terms, …) now pick up a newly installed or updated language pack's translations on their own; previously only a board that already had that language installed when its help pages were first seeded got the translation.
- Cleaned up leftover half-translated rows this left behind on some boards, and the equivalent leftover rows for trophy names/descriptions after a language pack import.
## Admin login, and other fixes
- Fixed a page-breaking script error that could appear on `/admin/login` after certain theme/script updates.
- A handful of interface strings (sign-in, sign-up, "mark forums read", forum watch and others) that were silently falling back to their raw, untranslated key instead of readable English text when a phrase row was missing now show the intended text instead.
- A rendering bug from an earlier migration left a small number of pages (a conversation's "loading…" text, two spots each on a thread and a profile page, on a few themes) printing a literal, unreadable code fragment instead of running it. Fixed at the source and for every page it had already reached.
## Notes for theme and add-on authors
- `RAXBOARD_ANALYTICS_SPEC.md` documents the Analytics data model and the read API for anyone building a custom reporting view. No theme-facing markup changed.
Get it
View on the Marketplace
— Posted automatically by the RaxBoard Marketplace.