projectsend.org

Changelog

ProjectSend 2.7.0

Four security fixes, folders you can manage over the API, and logo cropping.

Four security fixes, folders you can manage over the API, and logo cropping.

⚠️ Important — Do These Yourself

Everything else in this release happens on its own, and nothing here stops the upgrade.

  • If your installation cannot send email, accounts that sign in through Google, Microsoft or another provider can no longer set their own first password. The link to set it now arrives by email. Until mail works, an administrator can set the password from the person's account screen.
  • If an integration changes its own account's email address, password or two-factor authentication through the API, it now gets a 403. Do that from the profile screen instead. Changing somebody else's still works as before.

Added

  • Folders in the API: list, create, rename, move, delete and share them, and see where each one sits in the tree.
  • Crop your logo from Branding → Logo, and put the original back at any time.
  • "Import all" on the orphan files screen adopts every match in the background and shows its progress.
  • LDAP clients can sign in with their username as well as their email address, once you name the username attribute in Settings → LDAP.

Security

  • An API token can no longer change its own owner's password, email address or two-factor authentication, and setting somebody else's password now signs them out of the API.
  • The staff screen no longer changes your own email address or password without your current password.
  • An account that signs in through a provider now gets its first password from a link sent to its own email, not from whoever holds its browser session.
  • A staff member limited to some clients now sees and revokes only their own invitations and those into their clients' groups.
  • A staff member limited to some clients no longer sees the names of folders above the ones they can reach.
  • The orphan file tool can no longer be pointed at a file that belongs to somebody.
  • Creating a folder inside a public folder now needs permission to publish.

Changed

  • Your logo is shown larger on the sign-in and download pages.
  • The API token screen warns you when "Edit clients" or "Edit users" is chosen: a token with either can sign in as the accounts it may edit.
  • The Docker image no longer fills its log with passing health checks; failing ones still show.

Fixed

  • In the client portal, changing the sort inside a folder no longer jumps back to the top, and the chosen sort stays when you open a folder.
  • Third-party libraries are updated, including fixes for published security advisories.

Thanks to @simjiun, @sbouabid-sec, @veenone, @jiits, @cookiebaker and @01110111000001 for reporting and fixing.

Issues Closed Since 2.6.0

The summary above is what changed. This is the paper trail, for anyone who wants to read the original report.

  • #1798 — [ Feature request ] Branding : Site Name, Logo Size and Image Crop
  • #1806 — Sorting doesn't work with subfolders