Zum Inhalt springen

Athou Release Notes

30 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 7.3.2: Schutz vor Zugriff auf fremde Einträge

CommaFeed 7.3.2 verhindert, dass Nutzer fremde Einträge mit Stern oder Tag versehen und anschließend lesen können (GHSA-prfv-88mm-5gpg).

  • Prevent users from starring/tagging entries that are not theirs and subsequently reading them (GHSA-prfv-88mm-5gpg)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 7.3.1: Schutz vor Host-Header-Injection bei Passwortwiederherstellung

CommaFeed 7.3.1 schützt den Endpunkt zur Passwortwiederherstellung vor Host-Header-Injection und führt die Einstellung commafeed.password-recovery-public-base-url für die Basis-URL in Wiederherstellungs-E-Mails ein, die nur bei aktivierter Passwortwiederherstellung nötig ist (GHSA-hp8h-jqfm-v7x5).

  • Prevent Host header injection attacks on the password recovery endpoint. A new setting commafeed.password-recovery-public-base-url has been added to specify the base URL to use in password recovery emails (GHSA-hp8h-jqfm-v7x5). This setting is only required when the password recovery feature is enabled, which is not the default.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 7.3.0: Google Reader API und besserer SSRF-Schutz

CommaFeed 7.3.0 unterstützt die Google Reader API für native Mobile-Apps ohne Fever-API-Unterstützung, behebt das Profilmenü auf Mobilgeräten bei unten platzierten Aktionsbuttons, verbessert den SSRF-Schutz für IPv6 und ändert den Standardwert von blockLocalAddresses für mehr Sicherheit.

  • Add support for the Google Reader API for native mobile apps that don't support the Fever API
  • The profile menu now works again on mobile when action buttons are at the bottom of the screen
  • More SSRF protection regarding IPv6 (GHSA-q5qw-345w-55xg)
  • Changed the default value of blockLocalAddresses to make CommaFeed more secure out-of-the-box. See the "Access to local address blocked" section of the README if you subscribe to feeds that are only available on your local network.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 7.2.1: Favicons bei Sonderports und XSS-Schutz

CommaFeed 7.2.1 behandelt Favicons im Stammverzeichnis einer Domain bei Feeds mit nicht standardmäßigen Ports korrekt und filtert "javascript:"-URLs bereits beim Parsen, um XSS-Angriffe in Drittanbieter-Apps zu verhindern (GHSA-44pq-9929-f8mq).

  • correctly handle favicons hosted at the root of the domain for feeds with non-default ports
  • prevent XXS injections in third party apps. The CommaFeed React client was already stripping malicious "javascript:" URLs, they are now filtered during feed parsing and no longer stored in the database/served through the REST API (GHSA-44pq-9929-f8mq)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 7.2.0: Feed-Icons, Suche in markierten Einträgen, mehr Schutz

CommaFeed 7.2.0 unterstützt in Feeds deklarierte Icons, ermöglicht die Suche in markierten Einträgen, zeigt Fehlermeldungen beim Abonnieren wieder an, verbessert die Leistung der Feed-Aktualisierung, entfernt die eingestellte Pocket-Freigabe und stärkt den Schutz vor SSRF- und DDOS-Angriffen.

  • Add support for icons declared in feeds. This is useful for feeds exposed by RSS bridges (#2048)
  • Search now also works for starred entries (#2217)
  • The error message when subscribing to a feed is now properly displayed again
  • Small performance improvements to the feed refresh engine
  • Removed the Pocket sharing feature because the Pocket service has been discontinued
  • Prevent the image proxy feature to access any URL to avoid SSRF attacks
  • Strengthened the SSRF protection by also blocking ULA and CGNAT ranges (GHSA-hgrr-mjfp-gmr6)
  • Prevent DDOS attacks by filtering OPML files during imports (GHSA-83jp-rww3-57rr)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 7.1.0

Auf Mobilgeräten wird die Anzahl ungelesener Einträge jetzt im Header angezeigt, die Feed-Aktualisierung ist etwas performanter, und beim Herunterfahren bekommt sie über die neue Einstellung commafeed.shutdown-timeout (Standard 2 Sekunden) Zeit zum Abschließen.

  • Display the unread count in the header on mobile, since the tree is hidden by default and the unread count is not visible otherwise (#2055)
  • The feed refresh engine is now a little bit more performant (#2089)
  • On shutdown, give the feed refresh engine some time to finish refreshing feeds before killing it. This is controlled by the new commafeed.shutdown-timeout setting, which defaults to 2 seconds

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 7.0.0

Der JEXL-Filter zum automatischen Als-gelesen-Markieren wird durch einen visuellen Query Builder mit Common Expression Language ersetzt, pro Feed gibt es Push-Benachrichtigungen (ntfy, Gotify, Pushover) und automatisches Als-gelesen-Markieren nach einigen Tagen, und commafeed.http-client.block-local-addresses ist standardmäßig false, was ein SSRF-Risiko bedeuten kann.

  • Replaced the JEXL filter expression for marking feed entries as read automatically with a user-friendly visual query builder. Expressions are now evaluated with Common Expression Language, which is safer than JEXL and sanboxed by default.
  • Added a per-feed setting for sending push notifications to ntfy, Gotify or Pushover when new feed entries are discovered (#1610)
  • Added a per-feed setting for marking entries as read after a number of days (#2041)
  • The default value of commafeed.http-client.block-local-addresses is now false, allowing users to subscribe to feeds only available on their local network. This may be a security risk (SSRF) if your instance is accessible by untrusted users, so you may want to set it to true if you host a public instance of CommaFeed with user registeration enabled.
  • When commafeed.http-client.block-local-addresses is enabled, SSRF is now also mitigated by blocking public websites redirecting to local ones.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 6.2.0

Mit Stern markierte Einträge werden nicht mehr nach einer gewissen Zeit gelöscht, sondern dauerhaft behalten, wobei sich das alte Verhalten über die neue Einstellung commafeed.database.cleanup.keep-starred-entries wiederherstellen lässt.

  • Starred entries are no longer deleted after a certain amount of time, they are now kept indefinitely. The new commafeed.database.cleanup.keep-starred-entries setting can be disabled to restore the previous behavior if you want to keep deleting starred entries during normal entries cleanup (#1581)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 6.1.1

Alte markierte Einträge, die als gelesen markiert waren, werden jetzt wieder korrekt geladen.

  • Fix old starred entries not loading if they were marked as read (#2031)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 6.1.0

Beim Passwort-Reset wird kein Zufallspasswort mehr erzeugt, sondern der Nutzer legt auf einer eigenen Seite ein neues Passwort fest; außerdem wird beim ersten Start die Browsersprache verwendet, das Profilmenü schließt beim Scrollen und „Pull to refresh deaktivieren“ ist standardmäßig aus.

  • When clicking on the password reset link, a random password is no longer generated automatically. The user is now redirected to a page where they can set their own password (#2023)
  • Use browser preferred language instead of English when using CommaFeed for the first time (#2018)
  • The profile menu is now closed when scrolling the page (#2019)
  • The "disable pull to refresh" feature is now disabled by default (#2030)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 6.0.0

Beim ersten Start wird kein Standard-Admin-Konto mehr angelegt, sondern ein Einrichtungsassistent führt durch die Erstellung, die Passwortanforderungen sind über commafeed.users.minimum-password-length (Standard 4) gelockert, E-Mail-Adressen sind optional und Java 25+ ist nun erforderlich.

  • When booting CommaFeed for the first time, the default "admin" account is no longer created automatically. A setup wizard will guide you through the creation of an admin account
  • Default password complexity requirements have been lowered for local network deployments, where strict password rules are often unnecessary. The commafeed.users.strict-password-policy setting has been replaced by commafeed.users.minimum-password-length with a default value of 4 (#1916)
  • Email addresses are no longer required when creating users and when they update their profile. The commafeed.users.email-address-required setting has been added to restore the previous behavior (#1914)
  • Java 25+ is now required to build and run CommaFeed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 5.12.1

Das Favicon wird schärfer dargestellt, und die iOS-App ReadKit funktioniert nun über die Fever API.

  • The favicon is now crispier (#1978)
  • The ReadKit iOS app now works via the Fever API (#1602)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 5.12.0

Neue Einstellung zum Deaktivieren der „Pull to refresh“-Sperre, Emojis in Feeds werden korrekt angezeigt, ungültige relative URLs und große Feeds unter Java 24+ blockieren das Parsen nicht mehr, und das Kontextmenü zeigt „Star/Unstar“ nicht bei zu alten Einträgen.

  • Added a setting to disable the "disable pull to refresh" feature because it messes with some browsers (#1168)
  • Emojis in feeds are now correctly displayed (#1955)
  • Don't show "Star/Unstar" in the context menu if the entry is too old to be starred (#1935)
  • Invalid relative urls in feeds no longer prevent those feeds from being parsed (#1939)
  • Fix an issue that could prevent large feeds from being parsed when using Java 24+ (#1961)
  • Enforce user password validation when created in the admin view (#1937)
  • The process in the docker native image is now called "commafeed" instead of "application"

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 5.11.1

Das Suchlimit von 3 Zeichen wurde entfernt, und Feed-Filterausdrücke werden beim Speichern nicht mehr fälschlich in Kleinbuchstaben umgewandelt.

  • The search limit of 3 characters has been removed (#1887)
  • Fix an issue that caused feed filtering expressions to be incorrectly converted to lowercase when saving them (#1899)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 5.11.0

Beim Markieren aller Einträge als gelesen kann optional zur nächsten ungelesenen Kategorie oder zum nächsten ungelesenen Feed gewechselt werden, und die Google-Analytics-Unterstützung wurde entfernt.

  • Add an option to navigate to the next unread category/feed when marking all entries as read (#1807)
  • Google Analytics support has been removed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 5.10.0

Neben der Ungelesen-Anzahl eines Feeds zeigt ein Indikator neue Einträge bei geöffneter App an, Feeds mit großgeschriebenem HTTP:// oder HTTPS:// werden wieder korrekt behandelt, die aarch64-Version läuft auch auf dem Raspberry Pi 5 und die UI ist performanter.

  • Add an indicator next to each feed's unread count in the tree to show when new entries are discovered while the app is open (#1762)
  • Feeds with uppercase HTTP:// or HTTPS:// URLs are now correctly handled again
  • The aarch64 native executable now also works on the Raspberry Pi 5 (#1795)
  • Improve general performance of the UI by reducing the number of re-renders, especially when a lot of entries are displayed (#1087)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 5.9.0

Viele neue CSS-Klassen erleichtern eigene CSS-Regeln (mit Dokumentationslink im README), und statische Ressourcen werden deutlich länger gecacht.

  • A lot of CSS classes have been added to the elements of the application to ease custom CSS rules (#1757)
  • Added a link in the README to the documentation of the new CSS classes
  • Static resources are now cached for much longer (#1782)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 5.8.0

Die Akzentfarbe und die Schriftgröße der Einträge lassen sich einstellen, die Bestätigung für „alle als gelesen“ gilt nun auch für Shift+A, die Browsersprache wird berücksichtigt und der Standardwert für Einträge oberhalb der Auswahl beim Scrollen ist 1.

  • A color picker is now available on the settings page to change the orange accent of the application (#1598)
  • A font size slider is now available to change the size of the text of feed entries (#1462)
  • The "mark all as read" confirmation setting now also applies to the "shift+a" keyboard shortcut (#1744)
  • CommaFeed wil try to match the language of the browser before defaulting to english (#1767)
  • The default value for the number of entries to keep above the selected entry when scrolling is now 1 instead of 0 to match what other feed readers do

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 5.7.0

Neue Tastenkürzel Shift+J/Shift+K springen zum nächsten oder vorherigen Feed bzw. zur Kategorie mit ungelesenen Einträgen, außerdem wurden Feed-Header-Handling, gzip-Kompression, Tooltips in der mobilen Ansicht und der Bookmarklet-Generator korrigiert.

  • Add Shift+J/Shift+K keyboard shortcuts to navigate to the next/previous feed or category with unread entries (#1558)
  • Add the referrer "no-referrer" meta to index.html (#1724)
  • Load custom JS code when the app is done loading (#1724)
  • Correctly handle feeds that return an unmodified Last-Modified header but a different ETag header (#1746)
  • Restore gzip compression of responses that was accidentaly disabled since 5.0.0
  • Fix tooltips not showing up in mobile view
  • Fix the bookmarklet generator on the About page

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Commafeed von Athou

CommaFeed 5.6.1

Iframes in Feed-Einträgen werden wieder unterstützt, und für Arch Linux steht nun ein Paket zur Verfügung.

  • Restore support for iframes in feed entries (#1688)
  • There is now a package available for Arch Linux thanks to @dcelasun (#1691)

Originalquelle(öffnet in neuem Tab)Problem melden