惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
D
DataBreaches.Net
F
Fortinet All Blogs
阮一峰的网络日志
阮一峰的网络日志
博客园_首页
Apple Machine Learning Research
Apple Machine Learning Research
H
Help Net Security
M
MIT News - Artificial intelligence
美团技术团队
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The Cloudflare Blog
有赞技术团队
有赞技术团队
L
LangChain Blog
博客园 - Franky
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 【当耐特】
S
SegmentFault 最新的问题
V
Visual Studio Blog
Blog — PlanetScale
Blog — PlanetScale
Hugging Face - Blog
Hugging Face - Blog
B
Blog
I
InfoQ

Campfire Changelog

暂无文章

Campfire Changelog
ONCE · 2025-12-15 · via Campfire Changelog

1.4.3

Additions:

  • Admins now appear first in the list of users.

Fixes:

  • Messages with mentions rendering as errors sometimes.
  • Race condition during initial account creation that allowed two admins to get created.
  • Removing a ban is now properly labeled instead of showing up as “Ban”.
  • Non-admins being unable to change their room involvement.

1.4.2

Blind SSRF to link-local IPs via URL unfurling.

1.4.1

Messages with mentions created before Campfire 1.3.0 rendering as missing content.

1.4.0

Restrict room creation to only administrators.

1.3.0

Additions:

  • Add IP-based user banning.
  • Add dir="auto" to messages for right-to-left language support.
  • Add Japanese language translations.
  • Add GitHub Actions workflow to publish Docker image to GHCR with OpenContainers annotations.

Fixes:

  • Fix user impersonation via custom bot token (security fix).
  • Fix logout process erroring on localhost.
  • Fix cable traffic not being served under $SCRIPT_NAME.
  • Fix “Failed to get a ServiceWorkerRegistration” error.
  • Fix back button not working on profile page after form submission.
  • Fix room instance variable not being set in room direct edit/destroy.
  • Fix Let’s Encrypt autosetup instructions.
  • Fix grammar in README.
  • Fix typo.

Improvements:

  • Upgrade to Rails 8 and Ruby 3.4.5.
  • Speed up room’s initial load by reducing N+1 queries.
  • Install system dependencies in setup script.
  • Fix setup script to handle missing mise installation.
  • Bump Brakeman to latest version.

Cleanup:

  • Remove unused git source from Gemfile.
  • Remove unused event_log_controller.js file.

1.1.8

Fix improper bot authentication.

1.1.7

Suppress webhook notification if a bot messages itself.

1.1.6

Fix issue with forwarded headers when running behind an external proxy.

1.1.5

Fix incorrect configuration when running without TLS (via Thruster update).

1.1.4

  • Fix a bug that could cause images to appear broken.
  • Update Ruby version.

1.1.3

  • Sanitize OpenGraph content to prevent XSS attacks.
  • Improve system font stack on Windows.
  • Improve appearance and behavior of scroll bars on Windows.
  • Prevent signature verification errors with @mentions when restoring backups between different devices.
  • Isolate message rendering failures to ensure a problematic message does not prevent the rest of the room from rendering.
  • Fix a bug where the share button links use “example.com” instead of the application’s domain.
  • Accessibility improvements.
  • Ensure syntax highlighting is not lost when a message is edited.
  • Validate content type of OpenGraph images before rendering.
  • Disallow image tags in message body in order to guard against malicious image payloads.
  • Fix an issue where the sidebar tools is blurred in Safari 17.3.

1.1.2

Features & changes:

  • Add automatic syntax highlighting for code blocks.
  • Add an up-arrow shortcut to edit your last message.
  • Bot API: include room and message paths in webhook payload.
  • Accessibility improvements.
  • Use Thruster gem, rather than vendored version.
  • Add smaller logo variant in application manifest.

Bugfixes:

  • Ensure attachment filename is properly escaped when displayed during upload.
  • Ensure only a single connection refresh timer runs at a time.
  • Fix issue where opening the app would not reliably return to the last visited room.
  • Guard against DNS rebind attacks when creating link previews.
  • Use unguessable tokens in avatar URLs to prevent discovery via enumeration.
  • Ensure messages scroll fully into view when editing in Chrome.
  • Don’t broadcast room updates to users who aren’t members of the room.

1.1.1

Fix confusing iconography in flash messages.

1.1.0

  • Add the Chat Bot API: you can now create chat bots for your Campfire instance using a simple HTTP API for sending and receiving messages and attachments.
  • Add Custom CSS: you can now enter your own CSS styles to modify the appearance of your Campfire instance.
  • Add a warning style to messages that fail to send due to network or server errors.
  • Improve accessibility of alert messages.
  • Improve appearance and handling of messages with link previews.
  • Order search results by recency.
  • Improve appearance of @mentions in messages.
  • Ensure users who are removed from a room are disconnected from it immediately.
  • Ensure starting a Ping with someone moves their avatar to the front of the list.
  • Fix an issue where attempting to change a password on Safari caused the form to submit unexpectedly.
  • Fix an issue where Campfire join URLs displayed incorrectly in Apple Messages.
  • Add a copy permalink button to the message action menu.
  • Add download and share buttons to non-image attachments.

1.0.3

  • Improve handling and appearance of link previews in chat messages.
  • Fix an issue where replying to a message may cause a “Content missing” error to be displayed.
  • Restrict autocomplete responses to the rooms each user has access to.
  • Refine behaviour of message actions menu.
  • Upgrade Trix editor for better handling of autocorrected text.

1.0.2

  • Improve design for message actions popup menu.
  • Improve mobile chat layout.
  • Improve design for link previews to display longer excerpts and larger images.
  • Gracefully handle exceptions when generating embedded link previews. Fixes a crash when generating previews for links with invalid OpenGraph metadata.

1.0.1

Escape name in autocomplete user response. Fixes an XSS vulnerability in Campfire’s autocomplete handler.

1.0.0

Campfire goes live.

ONCE™ products are designed, built, and backed by 37signals™. Copyright © 37signals LLC. All rights reserved.
Anyone buying, using, or receiving a ONCE™ product is subject to our software license agreement.