Autor del tema
#1
RaxBoard Core — Core
A new release is now available on the RaxBoard Marketplace.
Version: 1.9.4 (build 20260929)
Compatibility: RaxBoard >=1.0.0
What's new
# RaxBoard 1.9.4 (build 20260929)
14 new migrations (1169–1183) over 1.9.3. No schema breaks; the upgrade is an overlay plus `migrate:run`. **This is a security release — update promptly.** Recommended order on a board: this core update first, then the add-ons and themes published alongside it.
## Security
- **Hidden content (`[hide…]` tags) no longer leaks outside the post.** A member who did not meet a hidden block's condition saw the locked placeholder in the post, but the text itself could still be read elsewhere: in the data behind the Reply / Quote buttons, in a post's edit history (which also showed any post — deleted, awaiting approval or in a private forum — to any member), in the REST API (post and thread endpoints, API search, profile walls), in the AI bot's context, in club RSS feeds, in private-message data, on profile "Posts" / "Threads" tabs and wall posts (open to guests), and in bookmarks (lists, public lists, and bookmarking any post by id). Every one of these now applies the same rule as the thread page. The API also stopped returning deleted, unapproved and private-forum posts and posters' IP addresses to keys that should not see them. The routine that removes hidden blocks from excerpts, notifications, meta tags and AI input now follows the post parser exactly — some spellings (`[hidegroup = 3]`, tags spanning other formatting, very large posts) used to come through whole.
- **Link previews can no longer be pointed at internal addresses (SSRF).** The preview proxy behind `/api/unfurl` accepted IPv6 addresses (`[::1]`, `[::ffff:127.0.0.1]`, private ranges) and followed redirects from a public page to `127.0.0.1` or a cloud metadata address. Every address a link resolves to is now checked, every redirect is re-checked, the connection is pinned to the checked address, only ports 80/443 are used, and the endpoint is rate-limited per visitor with a cap on queued links.
- A failing "Run now" in Admin → Cron no longer puts the server's file path into the page address (and from there into browser history and access logs).
- Removed a stray `--nohdr` file that 1.9.0–1.9.3 shipped at the forum root: a leftover cookie file from our build machine holding an expired development session — no data of any board. On forum-root installs it could be downloaded. The update deletes it, and the packaging checks now refuse such files.
## Threads and forums
- **Read and unread threads now look different.** Titles of threads you have already read show in normal weight in forum thread lists, What's New and the forum index "last post" line; the board now records which threads a member has read (members only).
- **Pasted links become links.** A bare `https://…` or `www.…` address in a post is linked automatically (never inside code, `[plain]`, `[url]`, `[img]`, mentions and similar; trailing punctuation is left out). The "Disable auto-linking" setting now works. Also fixed double-escaped `&` in `[url]`, `[img]`, `[email]` and `[media]` links.
- The "go to message" arrow on a quote scrolls to the quoted post and stays there — it used to jump to the top of the page a moment later. Cmd/Ctrl-click opens it in a new tab, and Back / Forward keep the right content.
- Image user banners (rank images) under a poster's name wrap and scale instead of overflowing on phones; the reaction picker opens in the right place on every reaction bar, including right-to-left languages.
- On phones the back-to-top button is smaller, respects the screen's safe areas, and gets out of the way of buttons it would cover.
## Avatars
- **A new avatar shows everywhere at once.** Uploading from the profile header updated only the profile itself; the forum home page, thread lists and widgets kept the old picture. Fixed, and the update repairs the avatars this left out of date and makes browsers fetch the corrected files.
- **Avatar uploads from phones work and explain themselves.** A large camera photo is resized in the browser before upload; an image the board still cannot accept (HEIC, too large for the server, wrong dimensions) now shows a message instead of silently reloading the page. Photos keep their correct orientation. The cover-photo uploader no longer fails silently either.
- The avatar in a post's edit history is the current one.
## AI tools
- **Thread summary:** long threads now include their newest messages in what the AI reads; the summary is shown formatted instead of as raw BBCode; a timeout, a lost connection and a server error each say what happened, and a failure no longer lands in the result box with its Copy / Add-to-reply buttons.
- "Reply with AI" and "Create with AI" report failures the same way (no more bare "Error" or "[object Object]").
- Admin → AI → "Test connection" now fails, with an explanation, when the provider answers with an empty reply — typical of reasoning models that spend the whole token budget on hidden thinking, which made every AI tool fail while the test said "Connection OK".
- Bullet lists in AI results line up correctly in right-to-left languages, and the error text has proper contrast.
## Hosting compatibility
- **Works on hosts that disable cURL.** Every outbound request (payments, social login, AI providers, webhooks, search engines, push, link previews, feeds, webmentions, GIF search) goes through one HTTP client: cURL when it is available, otherwise PHP sockets, otherwise PHP's stream wrapper. The installer now lists cURL as recommended rather than required and shows which outbound HTTPS method the host allows.
- Functions that shared hosts commonly disable (`fpassthru`, `readfile`, `ini_set`, `set_time_limit`, `mail`, `fsockopen`, `getmypid`, `exec`) are checked before use instead of causing a fatal error.
- Long-running cron and queue processes reconnect after "MySQL server has gone away" (never inside a transaction; a write is retried only when it is safe to).
- An upload larger than the server's `post_max_size` now gets a clear "the file is larger than this server accepts" message instead of a misleading "session token missing" page.
## Admin
- **The thread-prefix editor works again** — live preview, icon grid and colour label had stopped responding on boards where the old colour/design controls were removed in 1.8.9.
- The user group form explains that an empty User Title falls back to the automatic user title ladder, and where to switch that off.
- Add-on hook points: every hook point the templates render is now registered, so add-ons using them no longer fill the error log with "unknown hook point" warnings (one board logged close to 6,000 a day). `admin_dashboard_widgets` now appears on the dashboard, and `page_header_after` / `page_footer_before` render.
- Custom CSS editor: Windows line endings no longer push a large stylesheet over the 500 KB limit, and saving keeps the theme's shipped baseline.
- Error reports sent from the board only include errors from the board's own files.
## Notes for theme and add-on authors
- Outbound HTTP: use `App\Infrastructure\Http\HttpClient::request()` instead of raw `curl_*` or `file_get_contents()` on a URL; for a URL a visitor supplied, validate it with `App\Infrastructure\Http\OutboundUrlGuard` and pass its `pins` as the `resolve` option.
- Thread rows receive `is_read` / `is_unread` (members only); the `rb-th-read` class marks a read title. Theme bundles imported on 1.9.4 get the hook added automatically.
Get it
View on the Marketplace
— Posted automatically by the RaxBoard Marketplace.
A new release is now available on the RaxBoard Marketplace.
Version: 1.9.4 (build 20260929)
Compatibility: RaxBoard >=1.0.0
What's new
# RaxBoard 1.9.4 (build 20260929)
14 new migrations (1169–1183) over 1.9.3. No schema breaks; the upgrade is an overlay plus `migrate:run`. **This is a security release — update promptly.** Recommended order on a board: this core update first, then the add-ons and themes published alongside it.
## Security
- **Hidden content (`[hide…]` tags) no longer leaks outside the post.** A member who did not meet a hidden block's condition saw the locked placeholder in the post, but the text itself could still be read elsewhere: in the data behind the Reply / Quote buttons, in a post's edit history (which also showed any post — deleted, awaiting approval or in a private forum — to any member), in the REST API (post and thread endpoints, API search, profile walls), in the AI bot's context, in club RSS feeds, in private-message data, on profile "Posts" / "Threads" tabs and wall posts (open to guests), and in bookmarks (lists, public lists, and bookmarking any post by id). Every one of these now applies the same rule as the thread page. The API also stopped returning deleted, unapproved and private-forum posts and posters' IP addresses to keys that should not see them. The routine that removes hidden blocks from excerpts, notifications, meta tags and AI input now follows the post parser exactly — some spellings (`[hidegroup = 3]`, tags spanning other formatting, very large posts) used to come through whole.
- **Link previews can no longer be pointed at internal addresses (SSRF).** The preview proxy behind `/api/unfurl` accepted IPv6 addresses (`[::1]`, `[::ffff:127.0.0.1]`, private ranges) and followed redirects from a public page to `127.0.0.1` or a cloud metadata address. Every address a link resolves to is now checked, every redirect is re-checked, the connection is pinned to the checked address, only ports 80/443 are used, and the endpoint is rate-limited per visitor with a cap on queued links.
- A failing "Run now" in Admin → Cron no longer puts the server's file path into the page address (and from there into browser history and access logs).
- Removed a stray `--nohdr` file that 1.9.0–1.9.3 shipped at the forum root: a leftover cookie file from our build machine holding an expired development session — no data of any board. On forum-root installs it could be downloaded. The update deletes it, and the packaging checks now refuse such files.
## Threads and forums
- **Read and unread threads now look different.** Titles of threads you have already read show in normal weight in forum thread lists, What's New and the forum index "last post" line; the board now records which threads a member has read (members only).
- **Pasted links become links.** A bare `https://…` or `www.…` address in a post is linked automatically (never inside code, `[plain]`, `[url]`, `[img]`, mentions and similar; trailing punctuation is left out). The "Disable auto-linking" setting now works. Also fixed double-escaped `&` in `[url]`, `[img]`, `[email]` and `[media]` links.
- The "go to message" arrow on a quote scrolls to the quoted post and stays there — it used to jump to the top of the page a moment later. Cmd/Ctrl-click opens it in a new tab, and Back / Forward keep the right content.
- Image user banners (rank images) under a poster's name wrap and scale instead of overflowing on phones; the reaction picker opens in the right place on every reaction bar, including right-to-left languages.
- On phones the back-to-top button is smaller, respects the screen's safe areas, and gets out of the way of buttons it would cover.
## Avatars
- **A new avatar shows everywhere at once.** Uploading from the profile header updated only the profile itself; the forum home page, thread lists and widgets kept the old picture. Fixed, and the update repairs the avatars this left out of date and makes browsers fetch the corrected files.
- **Avatar uploads from phones work and explain themselves.** A large camera photo is resized in the browser before upload; an image the board still cannot accept (HEIC, too large for the server, wrong dimensions) now shows a message instead of silently reloading the page. Photos keep their correct orientation. The cover-photo uploader no longer fails silently either.
- The avatar in a post's edit history is the current one.
## AI tools
- **Thread summary:** long threads now include their newest messages in what the AI reads; the summary is shown formatted instead of as raw BBCode; a timeout, a lost connection and a server error each say what happened, and a failure no longer lands in the result box with its Copy / Add-to-reply buttons.
- "Reply with AI" and "Create with AI" report failures the same way (no more bare "Error" or "[object Object]").
- Admin → AI → "Test connection" now fails, with an explanation, when the provider answers with an empty reply — typical of reasoning models that spend the whole token budget on hidden thinking, which made every AI tool fail while the test said "Connection OK".
- Bullet lists in AI results line up correctly in right-to-left languages, and the error text has proper contrast.
## Hosting compatibility
- **Works on hosts that disable cURL.** Every outbound request (payments, social login, AI providers, webhooks, search engines, push, link previews, feeds, webmentions, GIF search) goes through one HTTP client: cURL when it is available, otherwise PHP sockets, otherwise PHP's stream wrapper. The installer now lists cURL as recommended rather than required and shows which outbound HTTPS method the host allows.
- Functions that shared hosts commonly disable (`fpassthru`, `readfile`, `ini_set`, `set_time_limit`, `mail`, `fsockopen`, `getmypid`, `exec`) are checked before use instead of causing a fatal error.
- Long-running cron and queue processes reconnect after "MySQL server has gone away" (never inside a transaction; a write is retried only when it is safe to).
- An upload larger than the server's `post_max_size` now gets a clear "the file is larger than this server accepts" message instead of a misleading "session token missing" page.
## Admin
- **The thread-prefix editor works again** — live preview, icon grid and colour label had stopped responding on boards where the old colour/design controls were removed in 1.8.9.
- The user group form explains that an empty User Title falls back to the automatic user title ladder, and where to switch that off.
- Add-on hook points: every hook point the templates render is now registered, so add-ons using them no longer fill the error log with "unknown hook point" warnings (one board logged close to 6,000 a day). `admin_dashboard_widgets` now appears on the dashboard, and `page_header_after` / `page_footer_before` render.
- Custom CSS editor: Windows line endings no longer push a large stylesheet over the 500 KB limit, and saving keeps the theme's shipped baseline.
- Error reports sent from the board only include errors from the board's own files.
## Notes for theme and add-on authors
- Outbound HTTP: use `App\Infrastructure\Http\HttpClient::request()` instead of raw `curl_*` or `file_get_contents()` on a URL; for a URL a visitor supplied, validate it with `App\Infrastructure\Http\OutboundUrlGuard` and pass its `pins` as the `resolve` option.
- Thread rows receive `is_read` / `is_unread` (members only); the `rb-th-read` class marks a read title. Theme bundles imported on 1.9.4 get the hook added automatically.
Get it
View on the Marketplace
— Posted automatically by the RaxBoard Marketplace.