diff options
author | Lain Soykaf <lain@lain.com> | 2025-03-01 18:14:36 +0400 |
---|---|---|
committer | Lain Soykaf <lain@lain.com> | 2025-03-01 18:14:36 +0400 |
commit | a24e894b2ba90a353c6a069cf149dc6f9bd8f703 (patch) | |
tree | 85c0957c53e036ac1a5adabd03a3877df515e468 /CHANGELOG.md | |
parent | e88eb24443cf49309cd43f7eb6fbfb268e2eb30a (diff) | |
download | pleroma-a24e894b2ba90a353c6a069cf149dc6f9bd8f703.tar.gz pleroma-a24e894b2ba90a353c6a069cf149dc6f9bd8f703.zip |
Update changelog
Diffstat (limited to 'CHANGELOG.md')
-rw-r--r-- | CHANGELOG.md | 27 |
1 files changed, 27 insertions, 0 deletions
diff --git a/CHANGELOG.md b/CHANGELOG.md index 71178c89a..657422689 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,33 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/). +## 2.9.0 + +### Security +- Require HTTP signatures (if enabled) for routes used by both C2S and S2S AP API +- Fix several spoofing vectors + +### Changed +- Performance: Use 301 (permanent) redirect instead of 302 (temporary) when redirecting small images in media proxy. This allows browsers to cache the redirect response. + +### Added +- Include "published" in actor view +- Link to exported outbox/followers/following collections in backup actor.json +- Hashtag following +- Allow to specify post language + +### Fixed +- Verify a local Update sent through AP C2S so users can only update their own objects +- Fix Mastodon incoming edits with inlined "likes" +- Allow incoming "Listen" activities +- Fix missing check for domain presence in rich media ignore_host configuration +- Fix Rich Media parsing of TwitterCards/OpenGraph to adhere to the spec and always choose the first image if multiple are provided. +- Fix OpenGraph/TwitterCard meta tag ordering for posts with multiple attachments +- Fix blurhash generation crashes + +### Removed +- Retire MRFs DNSRBL, FODirectReply, and QuietReply + ## 2.8.0 ### Changed |