Zum Inhalt springen

Payload Release Notes

10 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Payload

Payload v4.0.0-canary.38 mit payload.validate() und neuen Features

Version 4.0.0-canary.38 hebt die minimale Next.js-Version auf 16.4 an und ergänzt unter anderem die Operation payload.validate() zur Validierung von Dokumenten auf Abruf, die Verwaltung von LLM-Anweisungen im Admin, deren Aufnahme in CLI- und MCP-Schemas, File Transformers mit Migration der Upload-Größen zu Variants sowie eine Datenbank-Kopiermethode.

v4.0.0-canary.38 (2026-10-07)

🚀 Features

  • bump min. next.js version to 16.4 (#18569) (9bc6cae)
  • add new payload.validate() operation for on-demand validation of documents (#17557) (019deca)
  • manage LLM instructions in the admin (#18373) (4d0796c)
  • include configured LLM instructions in CLI and MCP schemas (#18372) (4d7a5ba)
  • improve PR demo scrolling and publishing (#18542) (32b5694)
  • add file transformers and migrate upload sizes to variants (#17827) (ed0e138)
  • add database copy method (#18453) (e6cd442) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Payload

Payload v4.0.0-canary.37: Neue Standards und Upgrade-Befehl

Payload v4.0.0-canary.37 setzt in der Local API overrideAccess standardmäßig auf false, veröffentlicht standardmäßig die aktive Locale (die Option defaultLocalePublishOption entfällt), ergänzt einen agentengestützten Upgrade-Befehl im Codemod und die Option devServerExternalPackages für withPayload in tanstack-start und behebt mehrere Fehler, darunter die veraltete mongodb-Option new, geerbte Leserechte für Collection-Versionen und die Größe von SQLite-Batch-Inserts.

v4.0.0-canary.37 (2026-09-24)

🚀 Features

  • default overrideAccess to false in the Local API (#17869) (744bfcf)
  • publish active locale by default, remove defaultLocalePublishOption (#17874) (5a6d003)
  • codemod: add agent-assisted upgrade command (#17825) (c44404c)
  • tanstack-start: add devServerExternalPackages option to withPayload (#17631) (346bd50)

🐛 Bug Fixes

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Payload

Payload v3.90.2: Mehrere Fehlerbehebungen in Core und Plugins

Payload v3.90.2 behebt mehrere Fehler, unter anderem beim Await der slugify-Funktion, bei next.config trailingSlash, bei alwaysInsertFields im plugin-cloud-storage, bei Abstürzen der create/update-Tools in plugin-mcp unter TypeScript 6, beim Formular-Refresh im plugin-multi-tenant sowie unnötige Rerenders des Client-Upload-Handlers.

v3.90.2 (2026-09-23)

🐛 Bug Fixes

  • await slugify func to match type (#18181) (3fad98e)
  • next: remove invalid libsql tracing include (#18238) (972a4fb)
  • next: support next.config trailingSlash (#18207) (05e49da)
  • plugin-cloud-storage: forward alwaysInsertFields when the plugin is enabled (#18222) (f5d261d)
  • plugin-mcp: create/update tools crash the MCP endpoint under TypeScript 6 ("use strict" prologue) (#17109) (e6efd70)
  • plugin-multi-tenant: avoid refreshing forms without stale tenant cookie (#18245) (a815140)
  • ui: prevent client upload handler rerenders (#18184) (b382576)

⚙️ CI …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Payload

Payload v3.90.1: Fehler bei verschachtelten Relationship-Feldern behoben

Payload v3.90.1 behebt einen Fehler, bei dem where-Abfragen des übergeordneten Elements fälschlich in verschachtelte Relationship-Felder übernommen wurden.

v3.90.1 (2026-09-18)

🐛 Bug Fixes

  • do not carry parent where queries into nested relationship fields (#18212) (d5ead4b)

🏡 Chores

🤝 Contributors

  • Jarrod Flesch (@JarrodMFlesch)
  • German Jablonski (@GermanJablo)
  • Jessica Rynkar (@JessRynkar)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Payload

Payload v3.90.0: Kritische Sicherheitsfixes, schnell installieren

Payload v3.90.0 enthält kritische Sicherheitsfixes und sollte schnellstmöglich installiert werden, unter anderem widerrufen Passwortänderungen andere Sitzungen, Passwort-Resets heben Sperren auf, Forgot-Password wird gedrosselt und Nutzer-Collections erhalten das neue Feld resetPasswordRequestedAt, weshalb Typen neu generiert und bei relationalen Datenbanken eine Migration ausgeführt werden müssen.

v3.90.0 (2026-09-18)

⚠️ This release contains a set of critical security fixes. Please review the following notes and upgrade as soon as possible. Even if none of the listed items below affect you, we still recommend updating as soon as possible.

These notes only cover the behavior, configuration, and API-surface changes that projects may need to react to when upgrading. Exploit details, attack surface descriptions, and severity are intentionally omitted.

CVE and GHSA identifiers for the underlying issues are published separately.

How to read this document

Every entry has: Affected if you (concrete conditions - if none apply, no action is required), and Action required.

After upgrading:

  • Regenerate your payload types: pnpm payload generate:types
  • If you are using a relational database, you will need to create and run a migration:
pnpm payload migrate:create <migration-name>
pnpm payload migrate

Password changes now revoke other sessions

  • No action needed.

Password reset now clears lockouts; forgot-password is throttled

  • Adds new resetPasswordRequestedAt field to user collections

  • Action required:

    • Regenerate types: pnpm payload generate:types
    • If using a relational database, perform migration:
pnpm payload migrate:create add-reset-password-requested-at
pnpm payload migrate
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Payload

Payload v3.89.0: Warning-Banner und Fehlerbehebungen

Payload v3.89.0 ergänzt einen Warning-Typ für Banner in der UI und behebt Fehler, darunter Speicherpufferung großer Client-Uploads, einen 500-Fehler in der Versionsdiff-Ansicht, außerdem wird Next auf 16.3.3 aktualisiert und es gibt Verbesserungen bei db-mongodb und drizzle.

v3.89.0 (2026-09-10)

🚀 Features

🐛 Bug Fixes

  • avoid buffering large client uploads into memory (#17872) (e896688)
  • "No client field found for ..." 500 error in version diff (#18001) (88f0622)
  • upgrade next to 16.3.3 across core and templates (#17933) (24164d8)
  • db-mongodb: avoid unnecessary aggregation when no joins are selected (#17785) (9a309af)
  • drizzle: preserve omitted hasMany selects (#18085) (ee7c00c)
  • drizzle: warn on truncated identifiers, throw on collisions (#17650) (52c4d70) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Payload

Payload 3.88.0: Fixes bei Multipart-Parsing und Copy-Paste, Next.js 16.3.0

Payload v3.88.0 behebt Probleme beim Multipart-Content-Type-Parsing und beim Kopieren und Einfügen in der UI, verbessert die Standard-Zugriffskontrolle der API-Keys-Collection in plugin-mcp und hebt das Template auf Next.js 16.3.0 an.

v3.88.0 (2026-08-11)

🐛 Bug Fixes

  • prevent multipart content-type backtracking (#17679) (a742140)
  • ui: tighten clipboard prefix matching to prevent sibling row leakage on copy/paste (#17595) (c6477b8)

🛠 Refactors

  • plugin-mcp: better access control defaults for api keys collection (#17751) (025581d)

📝 Templates

🤝 Contributors

  • Jarrod Flesch (@JarrodMFlesch)
  • Alessio Gravili (@AlessioGr)
  • Nate Lentz (@nathanlentz)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Payload

Payload 3.87.1: Fehlerbehebungen und Sicherheits-Updates für Abhängigkeiten

Payload v3.87.1 behebt mehrere Fehler, darunter den Next.js-Dev-HMR-Endpunkt, den Formularstatus im Link-Drawer des Lexical-Editors und das Template with-cloudflare-d1, und hebt mongoose, undici und @modelcontextprotocol/sdk wegen Sicherheitshinweisen an.

v3.87.1 (2026-08-06)

🐛 Bug Fixes

  • connect to the correct Next.js dev HMR endpoint per version (#17644) (291ac66)
  • db-mongodb: bump mongoose to 8.24.1 for GHSA-664h-wqgq-64gw (3.x backport of #17609) (#17608) (f039324)
  • deps: bump undici (#17630) (9e2c11e)
  • plugin-mcp: bump @modelcontextprotocol/sdk to 1.30.0 for GHSA-frvp-7c67-39w9 (3.x) (#17611) (0cb605d)
  • richtext-lexical: preserve link drawer form state (#17586) (90fb9e1)
  • templates: fix with-cloudflare-d1 build and bump dependencies (#17577) (ca3e899)

📚 Documentation …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Payload

Payload 3.87.0: Azure-Client-Uploads über 5 GB und mehrere Fehlerbehebungen

Payload v3.87.0 ermöglicht bei storage-azure mit chunkLargeFiles Client-Uploads von Dateien über 5 GB und behebt mehrere Fehler, etwa bei der Lokalisierung durch Tabs, count und countGlobalVersions mit Locale, Delete-Access beim Soft Delete, Entwurfstiteln in der Ordneransicht und null-Werten in Arrays und Blocks.

v3.87.0 (2026-07-31)

🚀 Features

  • storage-azure: client uploads with chunkLargeFiles can now support files larger than 5gb (#17319) (3c00a39)

🐛 Bug Fixes

  • preserve parent localization through tabs 3.x (#17591) (9c8d636)
  • replace image-size with image-dimensions dependency for upload dimensions (#17571) (2a99a01)
  • forward locale in count and countGlobalVersions (3.x) (#17547) (e042561)
  • pass id to delete access control on soft delete in updateByID (#17529) (a539f5b)
  • prefer draft titles in by folder view (#17412) (ef8a6a5)
  • arrays and blocks should handle null values, v3 backport (#17278) (2a69863) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Payload

Payload 3.86.0: disableBulkDelete, Übersetzungen im Form Builder, livePreview

Payload v3.86.0 führt collection-spezifisches disableBulkDelete, Übersetzungsunterstützung im plugin-form-builder und die Option livePreview.openByDefault ein und behebt außerdem Fehler bei schedulePublish, der URL-Prüfung isURLAllowed, deaktiviertem GraphQL und Dateizugriff bei Entwürfen.

v3.86.0 (2026-07-10)

🚀 Features

  • collection-level disableBulkDelete (#17207) (ca02cdc)
  • plugin-form-builder: v3 backport to support translations (#17255) (2cde8c8)
  • ui: add livePreview.openByDefault config option (#17213) (f23b693)

🐛 Bug Fixes

  • coerce schedulePublish doc.value to collection ID type before update (#17238) (7de11b2)
  • escape regex metacharacters in isURLAllowed pathname allow-list (#17237) (2061859)
  • respect disabled GraphQL config, v3 backport (#17228) (9e9c35a)
  • allow access to files reuploaded on a draft (#17209) (f02d22a) …

Originalquelle(öffnet in neuem Tab)Problem melden