Autor del tema
#1
RaxBoard Core — Core
A new release is now available on the RaxBoard Marketplace.
Version: 1.9.6 (build 20261005)
Compatibility: RaxBoard >=1.0.0
What's new
# RaxBoard 1.9.6 (build 20261005)
**Security release.** 34 new migrations (1187–1232) and six new tables over 1.9.5. The upgrade is an overlay plus `migrate:run` (or Admin → Updates). PHP 8.1 or newer is still required.
## Security
- **Members no longer see other members' edit history.** "View history" and `/posts/{id}/history` showed every earlier version of any post to any signed-in member, including text a moderator had removed. Two new permissions decide it now: "View edit history of any post" (copied from your existing "Edit any post" settings, so staff keep it) and "View edit history of own posts" (on by default).
- **Events:** the event page, its iCal download, calendar feeds, RSVP, event lists and the API now use one access check, so an event a visitor may not open can no longer be read through its .ics file or a feed.
- **Forums a member cannot open stay closed everywhere:** thread and forum addresses with an outdated name no longer redirect to (and reveal) the current title, and attachment downloads, moderator actions, post edit/delete, watching, votes, reactions, mentions, the AI assistant, `/api/forums`, search suggestions and bulk thread actions all check access. Moderators cannot move threads or posts into a forum they cannot open, and the "Receive conversations" permission is enforced.
- **The sitemap lists only what a guest can see** (forums, threads, tags and member profiles).
- **Admin → Options no longer prints saved passwords and secrets into the page.** A saved secret shows as "saved" and is kept when the field is left empty; it can be cleared explicitly. The option history no longer stores secret values, and existing entries are redacted on upgrade.
- **The admin login no longer skips two-step verification:** accounts with 2FA are sent to the main sign-in, which asks for the code.
- **Social sign-in follows your rules:** a sign-in with Google or another provider goes through your registration rules and the same account-state and two-step checks as a password sign-in, and links to an existing account by e-mail only when the provider has verified the address.
- **Signed updates and downloads:** the core updater accepts only a signed core-update authorization, and add-ons, themes and language packs are refused when their bytes do not match the signed checksum, when the authorization names another item, or when it would install an older version than the one you have.
- **Sealed (licensed) installs:** if a protected file is damaged or tampered with, visitors get an error page (503) instead of a board silently running without its licence checks; the admin panel stays open and shows a notice naming the file and how to recover.
- **Sessions:** two requests from the same visitor that finish at the same moment now merge their session changes instead of the later one wiping the earlier one.
- Licence keys are no longer written to the error log when the licence server answers with an error, and the public Webmention endpoint and several member pages no longer show raw error text.
- **Demo boards:** the admin restrictions for demo visitors are now enforced (template editing, add-on uploads, marketplace installs and core updates are blocked).
## New
- **Advanced reporting.** Members pick a reason — spam, harassment, hate speech, threats, sexual content, fraud, misinformation, copyright, personal information, "needs correction" or something else — add a note where the reason asks for one, follow their reports under **Account → My reports** and are told the outcome. Moderators get a prioritised queue, a detail page with every reporter and the history, and send an outcome and a message to the reporters. Admins edit the list under **Admin → Report reasons**. A second decision on the same content no longer fails.
- **Thread prefixes everywhere, in your colours:** forum last-post lines, the profile Threads tab, search results, trending and the featured strip. New option **Thread prefix display**: plain coloured text (default) or a filled badge; the prefix editor has its badge text colour back.
- **Phone verification by SMS or WhatsApp** (Twilio, WhatsApp Cloud API, Netgsm or your own HTTP gateway): at registration, on the member's Security page, and as a code for sign-ins from a new device. **Off by default.**
- **Sign in with Telegram** (OpenID Connect). **Off by default.** The OAuth settings now show the exact redirect address to register, the last error a provider returned, a "Test credentials" button and setup guides for Google and Telegram.
- **Bulk e-mail runs in the background:** Admin → Contact users returns at once and the messages are fed to the mail queue in small batches, so activation and password-reset mails are never stuck behind a broadcast.
- **Edit your own private messages in the reply editor**, with the toolbar, instead of a plain prompt.
- Stock labels such as "Member", "Moderator" and "Administrator" are shown in the visitor's language (8 languages); titles you typed yourself stay as typed.
- The featured content carousel can link items other than threads (for example Blog articles with Blog 2.0.12).
- **A clear PHP version check:** on PHP older than 8.1 the board and the installer show a "PHP update required" page (English or Turkish) instead of a blank white page.
## Fixed
- **Google sign-in for new accounts.** Since 1.6.0 the first sign-in with Google (or another provider) failed for anyone whose e-mail did not already belong to an account.
- **"Started by"** in the thread header names the thread's starter on every page (page 2 showed whoever posted first on that page), and the header's reply count is the thread's own.
- **Thread pages for moderators:** page counts and post positions match the posts a moderator actually sees, and notification links go straight to the post.
- Calendar (.ics) and RSS links download instead of being written into the page.
- **Redis and Memcached settings are now applied.** Before 1.9.6 they were saved but never used — if you entered one, make sure the server is reachable.
- **AI bot replies with Gemini 3 models were cut off mid-sentence** (the model's thinking used up the answer budget); AI moderation with these models no longer comes back empty, and a reply that still reaches its limit ends at the last full sentence.
- Confirming an e-mail address change works (the confirmation link was always rejected).
- Admin → Contact users: the "active in the last N days" and "inactive" criteria select the right members.
- Profile cover and avatar: the upload buttons show only for members allowed to use them and a refusal shows a message instead of raw JSON; phone photos no longer upload as a blank square, large cover photos are resized before upload, avatars are sharper.
- After posting a new thread its title draft is cleared, also on boards with translated addresses.
- Editor: no stray font-size codes after pasting or after select-all and delete; an inline edit keeps its own draft; in BBCode mode the toolbar writes into the visible text box.
- Permissions: a Deny is no longer cancelled by another group's Allow at forum level, and the "one account per IP address" registration option works.
- Add-on scheduled tasks declared in their manifest now run (for example MediaGallery's cleanup).
- Phones: the thread rating stays next to the reply and view counts, extra profile header buttons fold into a "⋯" menu, the online dot sits on the avatar's edge in every theme, and rating stars and dialog close buttons are easier to tap.
- Placeholder text in form fields has enough contrast in light mode.
## Admin
- Group, forum and moderator permission editors: readable headers, each permission's default and key, search and filters, bulk buttons, "copy from group", unsaved-change markers and screen-reader labels; moderator permissions are shown in the board language.
- Member IPs, last login and activity on the user edit screen (for admins allowed to see IPs); the member search no longer fails with a group fil
Get it
View on the Marketplace
— Posted automatically by the RaxBoard Marketplace.
A new release is now available on the RaxBoard Marketplace.
Version: 1.9.6 (build 20261005)
Compatibility: RaxBoard >=1.0.0
What's new
# RaxBoard 1.9.6 (build 20261005)
**Security release.** 34 new migrations (1187–1232) and six new tables over 1.9.5. The upgrade is an overlay plus `migrate:run` (or Admin → Updates). PHP 8.1 or newer is still required.
## Security
- **Members no longer see other members' edit history.** "View history" and `/posts/{id}/history` showed every earlier version of any post to any signed-in member, including text a moderator had removed. Two new permissions decide it now: "View edit history of any post" (copied from your existing "Edit any post" settings, so staff keep it) and "View edit history of own posts" (on by default).
- **Events:** the event page, its iCal download, calendar feeds, RSVP, event lists and the API now use one access check, so an event a visitor may not open can no longer be read through its .ics file or a feed.
- **Forums a member cannot open stay closed everywhere:** thread and forum addresses with an outdated name no longer redirect to (and reveal) the current title, and attachment downloads, moderator actions, post edit/delete, watching, votes, reactions, mentions, the AI assistant, `/api/forums`, search suggestions and bulk thread actions all check access. Moderators cannot move threads or posts into a forum they cannot open, and the "Receive conversations" permission is enforced.
- **The sitemap lists only what a guest can see** (forums, threads, tags and member profiles).
- **Admin → Options no longer prints saved passwords and secrets into the page.** A saved secret shows as "saved" and is kept when the field is left empty; it can be cleared explicitly. The option history no longer stores secret values, and existing entries are redacted on upgrade.
- **The admin login no longer skips two-step verification:** accounts with 2FA are sent to the main sign-in, which asks for the code.
- **Social sign-in follows your rules:** a sign-in with Google or another provider goes through your registration rules and the same account-state and two-step checks as a password sign-in, and links to an existing account by e-mail only when the provider has verified the address.
- **Signed updates and downloads:** the core updater accepts only a signed core-update authorization, and add-ons, themes and language packs are refused when their bytes do not match the signed checksum, when the authorization names another item, or when it would install an older version than the one you have.
- **Sealed (licensed) installs:** if a protected file is damaged or tampered with, visitors get an error page (503) instead of a board silently running without its licence checks; the admin panel stays open and shows a notice naming the file and how to recover.
- **Sessions:** two requests from the same visitor that finish at the same moment now merge their session changes instead of the later one wiping the earlier one.
- Licence keys are no longer written to the error log when the licence server answers with an error, and the public Webmention endpoint and several member pages no longer show raw error text.
- **Demo boards:** the admin restrictions for demo visitors are now enforced (template editing, add-on uploads, marketplace installs and core updates are blocked).
## New
- **Advanced reporting.** Members pick a reason — spam, harassment, hate speech, threats, sexual content, fraud, misinformation, copyright, personal information, "needs correction" or something else — add a note where the reason asks for one, follow their reports under **Account → My reports** and are told the outcome. Moderators get a prioritised queue, a detail page with every reporter and the history, and send an outcome and a message to the reporters. Admins edit the list under **Admin → Report reasons**. A second decision on the same content no longer fails.
- **Thread prefixes everywhere, in your colours:** forum last-post lines, the profile Threads tab, search results, trending and the featured strip. New option **Thread prefix display**: plain coloured text (default) or a filled badge; the prefix editor has its badge text colour back.
- **Phone verification by SMS or WhatsApp** (Twilio, WhatsApp Cloud API, Netgsm or your own HTTP gateway): at registration, on the member's Security page, and as a code for sign-ins from a new device. **Off by default.**
- **Sign in with Telegram** (OpenID Connect). **Off by default.** The OAuth settings now show the exact redirect address to register, the last error a provider returned, a "Test credentials" button and setup guides for Google and Telegram.
- **Bulk e-mail runs in the background:** Admin → Contact users returns at once and the messages are fed to the mail queue in small batches, so activation and password-reset mails are never stuck behind a broadcast.
- **Edit your own private messages in the reply editor**, with the toolbar, instead of a plain prompt.
- Stock labels such as "Member", "Moderator" and "Administrator" are shown in the visitor's language (8 languages); titles you typed yourself stay as typed.
- The featured content carousel can link items other than threads (for example Blog articles with Blog 2.0.12).
- **A clear PHP version check:** on PHP older than 8.1 the board and the installer show a "PHP update required" page (English or Turkish) instead of a blank white page.
## Fixed
- **Google sign-in for new accounts.** Since 1.6.0 the first sign-in with Google (or another provider) failed for anyone whose e-mail did not already belong to an account.
- **"Started by"** in the thread header names the thread's starter on every page (page 2 showed whoever posted first on that page), and the header's reply count is the thread's own.
- **Thread pages for moderators:** page counts and post positions match the posts a moderator actually sees, and notification links go straight to the post.
- Calendar (.ics) and RSS links download instead of being written into the page.
- **Redis and Memcached settings are now applied.** Before 1.9.6 they were saved but never used — if you entered one, make sure the server is reachable.
- **AI bot replies with Gemini 3 models were cut off mid-sentence** (the model's thinking used up the answer budget); AI moderation with these models no longer comes back empty, and a reply that still reaches its limit ends at the last full sentence.
- Confirming an e-mail address change works (the confirmation link was always rejected).
- Admin → Contact users: the "active in the last N days" and "inactive" criteria select the right members.
- Profile cover and avatar: the upload buttons show only for members allowed to use them and a refusal shows a message instead of raw JSON; phone photos no longer upload as a blank square, large cover photos are resized before upload, avatars are sharper.
- After posting a new thread its title draft is cleared, also on boards with translated addresses.
- Editor: no stray font-size codes after pasting or after select-all and delete; an inline edit keeps its own draft; in BBCode mode the toolbar writes into the visible text box.
- Permissions: a Deny is no longer cancelled by another group's Allow at forum level, and the "one account per IP address" registration option works.
- Add-on scheduled tasks declared in their manifest now run (for example MediaGallery's cleanup).
- Phones: the thread rating stays next to the reply and view counts, extra profile header buttons fold into a "⋯" menu, the online dot sits on the avatar's edge in every theme, and rating stars and dialog close buttons are easier to tap.
- Placeholder text in form fields has enough contrast in light mode.
## Admin
- Group, forum and moderator permission editors: readable headers, each permission's default and key, search and filters, bulk buttons, "copy from group", unsaved-change markers and screen-reader labels; moderator permissions are shown in the board language.
- Member IPs, last login and activity on the user edit screen (for admins allowed to see IPs); the member search no longer fails with a group fil
Get it
View on the Marketplace
— Posted automatically by the RaxBoard Marketplace.