From c9aab1e5d8c4cc221ce1b01878cf5aa0d75678a0b7b7798eda6a71239a96920a Mon Sep 17 00:00:00 2001 From: Dominik Heidler Date: Tue, 18 Jul 2023 15:56:55 +0000 Subject: [PATCH] =?UTF-8?q?-=20Version=201.11.36=20##=20=F0=9F=94=92=20Sec?= =?UTF-8?q?urity=20=20*=20Fixes=20for=20[CVE-2023-37259](https://cve.mitre?= =?UTF-8?q?.org/cgi-bin/cvekey.cgi=3Fkeyword=3DCVE-2023-37259)=20/=20[GHSA?= =?UTF-8?q?-c9vx-2g7w-rp65](https://github.com/matrix-org/matrix-react-sdk?= =?UTF-8?q?/security/advisories/GHSA-c9vx-2g7w-rp65)=20##=20=F0=9F=A6=96?= =?UTF-8?q?=20Deprecations=20=20*=20Deprecate=20customisations=20in=20favo?= =?UTF-8?q?ur=20of=20Module=20API=20([\#25736](https://github.com/vector-i?= =?UTF-8?q?m/element-web/pull/25736)).=20Fixes=20#25733.=20##=20=E2=9C=A8?= =?UTF-8?q?=20Features=20=20*=20OIDC:=20store=20initial=20screen=20in=20se?= =?UTF-8?q?ssion=20storage=20=20([\#25688](https://github.com/vector-im/el?= =?UTF-8?q?ement-web/pull/25688)).=20Fixes=20#25656.=20Contributed=20by=20?= =?UTF-8?q?@kerryarchibald.=20=20*=20Allow=20default=5Fserver=5Fconfig=20a?= =?UTF-8?q?s=20a=20fallback=20config=20([\#25682](https://github.com/vecto?= =?UTF-8?q?r-im/element-web/pull/25682)).=20Contributed=20by=20@ShadowRZ.?= =?UTF-8?q?=20=20*=20OIDC:=20remove=20auth=20params=20from=20url=20after?= =?UTF-8?q?=20login=20attempt=20([\#25664](https://github.com/vector-im/el?= =?UTF-8?q?ement-web/pull/25664)).=20Contributed=20by=20@kerryarchibald.?= =?UTF-8?q?=20=20*=20feat(faq):=20remove=20keyboard=20shortcuts=20button?= =?UTF-8?q?=20([\#9342](https://github.com/matrix-org/matrix-react-sdk/pul?= =?UTF-8?q?l/9342)).=20Fixes=20#22625.=20Contributed=20by=20@gefgu.=20=20*?= =?UTF-8?q?=20GYU:=20Update=20banner=20([\#11211](https://github.com/matri?= =?UTF-8?q?x-org/matrix-react-sdk/pull/11211)).=20Fixes=20#25530.=20Contri?= =?UTF-8?q?buted=20by=20@justjanne.=20=20*=20Linkify=20mxc://=20URLs=20as?= =?UTF-8?q?=20links=20to=20your=20media=20repo=20([\#11213](https://github?= =?UTF-8?q?.com/matrix-org/matrix-react-sdk/pull/11213)).=20Fixes=20#6942.?= =?UTF-8?q?=20=20*=20OIDC:=20Log=20in=20([\#11199](https://github.com/matr?= =?UTF-8?q?ix-org/matrix-react-sdk/pull/11199)).=20Fixes=20#25657.=20Contr?= =?UTF-8?q?ibuted=20by=20@kerryarchibald.=20=20*=20Handle=20all=20permitte?= =?UTF-8?q?d=20url=20schemes=20in=20linkify=20([\#11215](https://github.co?= =?UTF-8?q?m/matrix-org/matrix-react-sdk/pull/11215)).=20Fixes=20#4457=20a?= =?UTF-8?q?nd=20#8720.=20=20*=20Autoapprove=20Element=20Call=20oidc=20requ?= =?UTF-8?q?ests=20([\#11209](https://github.com/matrix-org/matrix-react-sd?= =?UTF-8?q?k/pull/11209)).=20Contributed=20by=20@toger5.=20=20*=20Allow=20?= =?UTF-8?q?creating=20knock=20rooms=20([\#11182](https://github.com/matrix?= =?UTF-8?q?-org/matrix-react-sdk/pull/11182)).=20Contributed=20by=20@charl?= =?UTF-8?q?ynguyen.=20=20*=20Expose=20and=20pre-populate=20thread=20ID=20i?= =?UTF-8?q?n=20devtools=20dialog=20([\#10953](https://github.com/matrix-or?= =?UTF-8?q?g/matrix-react-sdk/pull/10953)).=20=20*=20Hide=20URL=20preview?= =?UTF-8?q?=20if=20it=20will=20be=20empty=20([\#9029](https://github.com/m?= =?UTF-8?q?atrix-org/matrix-react-sdk/pull/9029)).=20=20*=20Change=20wordi?= =?UTF-8?q?ng=20from=20avatar=20to=20profile=20picture=20([\#7015](https:/?= =?UTF-8?q?/github.com/matrix-org/matrix-react-sdk/pull/7015)).=20Fixes=20?= =?UTF-8?q?vector-im/element-meta#1331.=20Contributed=20by=20@aaronraimist?= =?UTF-8?q?.=20=20*=20Quick=20and=20dirty=20devtool=20to=20explore=20state?= =?UTF-8?q?=20history=20([\#11197](https://github.com/matrix-org/matrix-re?= =?UTF-8?q?act-sdk/pull/11197)).=20=20*=20Consider=20more=20user=20inputs?= =?UTF-8?q?=20when=20calculating=20zxcvbn=20score=20([\#11180](https://git?= =?UTF-8?q?hub.com/matrix-org/matrix-react-sdk/pull/11180)).=20=20*=20GYU:?= =?UTF-8?q?=20Account=20Notification=20Settings=20([\#11008](https://githu?= =?UTF-8?q?b.com/matrix-org/matrix-react-sdk/pull/11008)).=20Fixes=20#2456?= =?UTF-8?q?7.=20Contributed=20by=20@justjanne.=20=20*=20Compound=20Typogra?= =?UTF-8?q?phy=20pass=20([\#11103](https://github.com/matrix-org/matrix-re?= =?UTF-8?q?act-sdk/pull/11103)).=20Fixes=20#25548.=20=20*=20OIDC:=20naviga?= =?UTF-8?q?te=20to=20authorization=20endpoint=20([\#11096](https://github.?= =?UTF-8?q?com/matrix-org/matrix-react-sdk/pull/11096)).=20Fixes=20#25574.?= =?UTF-8?q?=20Contributed=20by=20@kerryarchibald.=20##=20=F0=9F=90=9B=20Bu?= =?UTF-8?q?g=20Fixes=20=20*=20Fix=20read=20receipt=20sending=20behaviour?= =?UTF-8?q?=20around=20thread=20roots=20([\#3600](https://github.com/matri?= =?UTF-8?q?x-org/matrix-js-sdk/pull/3600)).=20=20*=20Fix=20missing=20metas?= =?UTF-8?q?pace=20notification=20badges=20([\#11269](https://github.com/ma?= =?UTF-8?q?trix-org/matrix-react-sdk/pull/11269)).=20Fixes=20#25679.=20=20?= =?UTF-8?q?*=20Make=20checkboxes=20less=20rounded=20([\#11224](https://git?= =?UTF-8?q?hub.com/matrix-org/matrix-react-sdk/pull/11224)).=20Contributed?= =?UTF-8?q?=20by=20@andybalaam.=20=20*=20GYU:=20Fix=20issues=20with=20audi?= =?UTF-8?q?ble=20keywords=20without=20activated=20mentions=20([\#11218](ht?= =?UTF-8?q?tps://github.com/matrix-org/matrix-react-sdk/pull/11218)).=20Co?= =?UTF-8?q?ntributed=20by=20@justjanne.=20=20*=20PosthogAnalytics=20unwatc?= =?UTF-8?q?h=20settings=20on=20logout=20([\#11207](https://github.com/matr?= =?UTF-8?q?ix-org/matrix-react-sdk/pull/11207)).=20Fixes=20#25703.?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit OBS-URL: https://build.opensuse.org/package/show/devel:languages:nodejs/element-web?expand=0&rev=45 --- element-web-1.11.34.tar.gz | 3 -- element-web-1.11.36.tar.gz | 3 ++ element-web.changes | 55 +++++++++++++++++++++++++++++++ element-web.spec | 2 +- npm-packages-offline-cache.tar.gz | 4 +-- 5 files changed, 61 insertions(+), 6 deletions(-) delete mode 100644 element-web-1.11.34.tar.gz create mode 100644 element-web-1.11.36.tar.gz diff --git a/element-web-1.11.34.tar.gz b/element-web-1.11.34.tar.gz deleted file mode 100644 index 872d375..0000000 --- a/element-web-1.11.34.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:54bfef3484f18135408b427ff253496e36a6ad3788b1df3c6c7ba0655e23e21b -size 1499270 diff --git a/element-web-1.11.36.tar.gz b/element-web-1.11.36.tar.gz new file mode 100644 index 0000000..109f5e9 --- /dev/null +++ b/element-web-1.11.36.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:bc87ffcfac3cba117bc2d2d278db2315958457591c2d21ec325878471f801a8c +size 1503594 diff --git a/element-web.changes b/element-web.changes index e272989..85112d7 100644 --- a/element-web.changes +++ b/element-web.changes @@ -1,3 +1,58 @@ +------------------------------------------------------------------- +Tue Jul 18 15:55:52 UTC 2023 - Dominik Heidler + +- Version 1.11.36 +## 🔒 Security + * Fixes for [CVE-2023-37259](https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=CVE-2023-37259) / [GHSA-c9vx-2g7w-rp65](https://github.com/matrix-org/matrix-react-sdk/security/advisories/GHSA-c9vx-2g7w-rp65) + +## 🦖 Deprecations + * Deprecate customisations in favour of Module API ([\#25736](https://github.com/vector-im/element-web/pull/25736)). Fixes #25733. + +## ✨ Features + * OIDC: store initial screen in session storage ([\#25688](https://github.com/vector-im/element-web/pull/25688)). Fixes #25656. Contributed by @kerryarchibald. + * Allow default_server_config as a fallback config ([\#25682](https://github.com/vector-im/element-web/pull/25682)). Contributed by @ShadowRZ. + * OIDC: remove auth params from url after login attempt ([\#25664](https://github.com/vector-im/element-web/pull/25664)). Contributed by @kerryarchibald. + * feat(faq): remove keyboard shortcuts button ([\#9342](https://github.com/matrix-org/matrix-react-sdk/pull/9342)). Fixes #22625. Contributed by @gefgu. + * GYU: Update banner ([\#11211](https://github.com/matrix-org/matrix-react-sdk/pull/11211)). Fixes #25530. Contributed by @justjanne. + * Linkify mxc:// URLs as links to your media repo ([\#11213](https://github.com/matrix-org/matrix-react-sdk/pull/11213)). Fixes #6942. + * OIDC: Log in ([\#11199](https://github.com/matrix-org/matrix-react-sdk/pull/11199)). Fixes #25657. Contributed by @kerryarchibald. + * Handle all permitted url schemes in linkify ([\#11215](https://github.com/matrix-org/matrix-react-sdk/pull/11215)). Fixes #4457 and #8720. + * Autoapprove Element Call oidc requests ([\#11209](https://github.com/matrix-org/matrix-react-sdk/pull/11209)). Contributed by @toger5. + * Allow creating knock rooms ([\#11182](https://github.com/matrix-org/matrix-react-sdk/pull/11182)). Contributed by @charlynguyen. + * Expose and pre-populate thread ID in devtools dialog ([\#10953](https://github.com/matrix-org/matrix-react-sdk/pull/10953)). + * Hide URL preview if it will be empty ([\#9029](https://github.com/matrix-org/matrix-react-sdk/pull/9029)). + * Change wording from avatar to profile picture ([\#7015](https://github.com/matrix-org/matrix-react-sdk/pull/7015)). Fixes vector-im/element-meta#1331. Contributed by @aaronraimist. + * Quick and dirty devtool to explore state history ([\#11197](https://github.com/matrix-org/matrix-react-sdk/pull/11197)). + * Consider more user inputs when calculating zxcvbn score ([\#11180](https://github.com/matrix-org/matrix-react-sdk/pull/11180)). + * GYU: Account Notification Settings ([\#11008](https://github.com/matrix-org/matrix-react-sdk/pull/11008)). Fixes #24567. Contributed by @justjanne. + * Compound Typography pass ([\#11103](https://github.com/matrix-org/matrix-react-sdk/pull/11103)). Fixes #25548. + * OIDC: navigate to authorization endpoint ([\#11096](https://github.com/matrix-org/matrix-react-sdk/pull/11096)). Fixes #25574. Contributed by @kerryarchibald. + +## 🐛 Bug Fixes + * Fix read receipt sending behaviour around thread roots ([\#3600](https://github.com/matrix-org/matrix-js-sdk/pull/3600)). + * Fix missing metaspace notification badges ([\#11269](https://github.com/matrix-org/matrix-react-sdk/pull/11269)). Fixes #25679. + * Make checkboxes less rounded ([\#11224](https://github.com/matrix-org/matrix-react-sdk/pull/11224)). Contributed by @andybalaam. + * GYU: Fix issues with audible keywords without activated mentions ([\#11218](https://github.com/matrix-org/matrix-react-sdk/pull/11218)). Contributed by @justjanne. + * PosthogAnalytics unwatch settings on logout ([\#11207](https://github.com/matrix-org/matrix-react-sdk/pull/11207)). Fixes #25703. + * Avoid trying to set room account data for pinned events as guest ([\#11216](https://github.com/matrix-org/matrix-react-sdk/pull/11216)). Fixes #6300. + * GYU: Disable sound for DMs checkbox when DM notifications are disabled ([\#11210](https://github.com/matrix-org/matrix-react-sdk/pull/11210)). Contributed by @justjanne. + * force to allow calls without video and audio in embedded mode ([\#11131](https://github.com/matrix-org/matrix-react-sdk/pull/11131)). Contributed by @EnricoSchw. + * Fix room tile text clipping ([\#11196](https://github.com/matrix-org/matrix-react-sdk/pull/11196)). Fixes #25718. + * Handle newlines in user pills ([\#11166](https://github.com/matrix-org/matrix-react-sdk/pull/11166)). Fixes #10994. + * Limit width of user menu in space panel ([\#11192](https://github.com/matrix-org/matrix-react-sdk/pull/11192)). Fixes #22627. + * Add isLocation to ComposerEvent analytics events ([\#11187](https://github.com/matrix-org/matrix-react-sdk/pull/11187)). Contributed by @andybalaam. + * Fix: hide unsupported login elements ([\#11185](https://github.com/matrix-org/matrix-react-sdk/pull/11185)). Fixes #25711. Contributed by @kerryarchibald. + * Scope smaller font size to user info panel ([\#11178](https://github.com/matrix-org/matrix-react-sdk/pull/11178)). Fixes #25683. + * Apply i18n to strings in the html export ([\#11176](https://github.com/matrix-org/matrix-react-sdk/pull/11176)). + * Inhibit url previews on MXIDs containing slashes same as those without ([\#11160](https://github.com/matrix-org/matrix-react-sdk/pull/11160)). + * Make event info size consistent with state events ([\#11181](https://github.com/matrix-org/matrix-react-sdk/pull/11181)). + * Fix markdown content spacing ([\#11177](https://github.com/matrix-org/matrix-react-sdk/pull/11177)). Fixes #25685. + * Fix font-family definition for emojis ([\#11170](https://github.com/matrix-org/matrix-react-sdk/pull/11170)). Fixes #25686. + * Fix spurious error sending receipt in thread errors ([\#11157](https://github.com/matrix-org/matrix-react-sdk/pull/11157)). + * Consider the empty push rule actions array equiv to deprecated dont_notify ([\#11155](https://github.com/matrix-org/matrix-react-sdk/pull/11155)). Fixes #25674. + * Only trap escape key for cancel reply if there is a reply ([\#11140](https://github.com/matrix-org/matrix-react-sdk/pull/11140)). Fixes #25640. + * Update linkify to 4.1.1 ([\#11132](https://github.com/matrix-org/matrix-react-sdk/pull/11132)). Fixes #23806. + ------------------------------------------------------------------- Fri Jun 23 14:24:44 UTC 2023 - Dominik Heidler diff --git a/element-web.spec b/element-web.spec index b1cfdaa..0592394 100644 --- a/element-web.spec +++ b/element-web.spec @@ -17,7 +17,7 @@ Name: element-web -Version: 1.11.34 +Version: 1.11.36 Release: 0 Summary: A glossy Matrix collaboration client - web files License: Apache-2.0 diff --git a/npm-packages-offline-cache.tar.gz b/npm-packages-offline-cache.tar.gz index 7577b93..a950e84 100644 --- a/npm-packages-offline-cache.tar.gz +++ b/npm-packages-offline-cache.tar.gz @@ -1,3 +1,3 @@ version https://git-lfs.github.com/spec/v1 -oid sha256:51144e8b5f6cc6ad19b647486729576be484bb178ec05639387ab037f940eb44 -size 96856691 +oid sha256:4bcb633d893652142428ce8129ebded5df480ec56b3d3ede53c5ad80f8e236a3 +size 98319487