Release v0.16.0
Pre-release
Pre-release
klcodanr
released this
26 Mar 15:25
·
395 commits
to master
since this release
Added support for LDAP authentication, UI tweaks and bug fixes.
CVE Advisory: CVE-2020-1949 - Improper Neutralization of Input During Web Page Generation
Scripts in Sling CMS do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.
Release notes
Bug
- [SLING-8871] - CMS - Upload Click Handler Registered Multiple Times
- [SLING-8872] - CMS - Fails to Extract JPEG Metadata
- [SLING-8919] - CMS - Error Dialogs Blank
- [SLING-8930] - CMS - i18n Not Reloading
- [SLING-8947] - CMS - Grid View Missing Fields
- [SLING-8953] - CMS - Closing Search Issues
- [SLING-8956] - Archetype Token Replacement Issues
- [SLING-8957] - Tika Fallback Provider Fails on Large Files
- [SLING-9000] - CMS - Reload Fails When Editing Component
- [SLING-9001] - CMS - Cannot Create Page without Template Policy
- [SLING-9226] - CMS - Move Fails with Same Name Resources
Improvement
- [SLING-8917] - CMS - Add Support for LDAP
- [SLING-8952] - CMS - Use Bulma Tags Instead of Buttons for Labelfield
- [SLING-8958] - Return Default Thumbnail on Error
- [SLING-9152] - CMS Reference - Use Commons Messaging Mail
- [SLING-9156] - CMS - Add Thumbnail to Search
- [SLING-9225] - CMS - Add JCR Cleanup Schedulers