CHANGELOG.md 11.6 KB
Newer Older
1 2 3 4 5
*   New applications get `config.cache_classes = false` in `config/environments/test.rb`
    unless `--skip-spring`.

    *Xavier Noria*

6 7 8 9
*   Autoloading during initialization is deprecated.

    *Xavier Noria*

10 11 12 13
*   Only force `:async` ActiveJob adapter to `:inline` during seeding.

    *BatedUrGonnaDie*

14 15 16 17 18
*   The `connection` option of `rails dbconsole` command is deprecated in
    favor of `database` option.

    *Yuji Yaginuma*

C
Connor Shea 已提交
19
*   Replace `chromedriver-helper` gem with `webdrivers` in default Gemfile.
20 21
    `chromedriver-helper` is deprecated as of March 31, 2019 and won't
    receive any further updates.
C
Connor Shea 已提交
22 23 24

    *Guillermo Iguaran‮*

X
Xavier Noria 已提交
25 26 27 28 29
*   Applications running in `:zeitwerk` mode that use `bootsnap` need
    to upgrade `bootsnap` to at least 1.4.2.

    *Xavier Noria*

30 31 32
*   Add `config.disable_sandbox` option to Rails console.

    This setting will disable `rails console --sandbox` mode, preventing
33
    developer from accidentally starting a sandbox console,
34
    which when left inactive, can cause the database server to run out of memory.
35 36 37

    *Prem Sichanugrist*

38 39 40 41
*   Add `-e/--environment` option to `rails initializers`.

    *Yuji Yaginuma*

42

E
eileencodes 已提交
43 44
## Rails 6.0.0.beta3 (March 11, 2019) ##

45 46 47 48 49 50 51 52 53 54 55
*   Generate random development secrets

    A random development secret is now generated to tmp/development_secret.txt

    This avoids an issue where development mode servers were vulnerable to
    remote code execution.

    Fixes CVE-2019-5420

    *Eileen M. Uchitelle*, *Aaron Patterson*, *John Hawthorn*

E
eileencodes 已提交
56

57 58
## Rails 6.0.0.beta2 (February 25, 2019) ##

59 60 61 62 63
*   Fix non-symbol access to nested hashes returned from `Rails::Application.config_for`
    being broken by allowing non-symbol access with a deprecation notice.

    *Ufuk Kayserilioglu*

64 65 66 67 68
*   Fix deeply nested namespace command printing.

    *Gannon McGibbon*


69 70
## Rails 6.0.0.beta1 (January 18, 2019) ##

71 72 73 74
*   Remove deprecated `after_bundle` helper inside plugins templates.

    *Rafael Mendonça França*

75 76 77 78
*   Remove deprecated support to old `config.ru` that use the application class as argument of `run`.

    *Rafael Mendonça França*

79 80 81 82
*   Remove deprecated `environment` argument from the rails commands.

    *Rafael Mendonça França*

83 84 85 86
*   Remove deprecated `capify!`.

    *Rafael Mendonça França*

87 88 89 90
*   Remove deprecated `config.secret_token`.

    *Rafael Mendonça França*

91 92 93 94
*   Seed database with inline ActiveJob job adapter.

    *Gannon McGibbon*

95 96 97 98 99 100 101 102
*   Add `rails db:system:change` command for changing databases.

    ```
    bin/rails db:system:change --to=postgresql
       force  config/database.yml
        gsub  Gemfile
    ```

103 104 105
    The change command copies a template `config/database.yml` with
    the target database adapter into your app, and replaces your database gem
    with the target database gem.
106 107 108

    *Gannon McGibbon*

B
bogdanvlviv 已提交
109 110 111 112
*   Add `rails test:channels`.

    *bogdanvlviv*

113 114 115 116
*   Use original `bundler` environment variables during the process of generating a new rails project.

    *Marco Costa*

117 118 119 120 121 122 123 124
*   Send Active Storage analysis and purge jobs to dedicated queues by default.

    Analysis jobs now use the `:active_storage_analysis` queue, and purge jobs
    now use the `:active_storage_purge` queue. This matches Action Mailbox,
    which sends its jobs to dedicated queues by default.

    *George Claghorn*

125 126 127 128
*   Add `rails test:mailboxes`.

    *George Claghorn*

129
*   Introduce guard against DNS rebinding attacks.
130

131
    The `ActionDispatch::HostAuthorization` is a new middleware that prevents
132 133 134 135 136 137 138 139 140 141 142
    against DNS rebinding and other `Host` header attacks. It is included in
    the development environment by default with the following configuration:

        Rails.application.config.hosts = [
          IPAddr.new("0.0.0.0/0"), # All IPv4 addresses.
          IPAddr.new("::/0"),      # All IPv6 addresses.
          "localhost"              # The localhost reserved domain.
        ]

    In other environments `Rails.application.config.hosts` is empty and no
    `Host` header checks will be done. If you want to guard against header
143
    attacks on production, you have to manually permit the allowed hosts
144 145 146 147 148 149 150 151 152 153 154 155
    with:

        Rails.application.config.hosts << "product.com"

    The host of a request is checked against the `hosts` entries with the case
    operator (`#===`), which lets `hosts` support entries of type `RegExp`,
    `Proc` and `IPAddr` to name a few. Here is an example with a regexp.

        # Allow requests from subdomains like `www.product.com` and
        # `beta1.product.com`.
        Rails.application.config.hosts << /.*\.product\.com/

156
    A special case is supported that allows you to permit all sub-domains:
157 158 159 160 161 162 163

        # Allow requests from subdomains like `www.product.com` and
        # `beta1.product.com`.
        Rails.application.config.hosts << ".product.com"

    *Genadi Samokovarov*

164 165 166 167
*   Remove redundant suffixes on generated helpers.

    *Gannon McGibbon*

168 169 170 171
*   Remove redundant suffixes on generated integration tests.

    *Gannon McGibbon*

172 173 174 175
*   Fix boolean interaction in scaffold system tests.

    *Gannon McGibbon*

176 177 178 179
*   Remove redundant suffixes on generated system tests.

    *Gannon McGibbon*

180 181 182 183 184 185
*   Add an `abort_on_failure` boolean option to the generator method that shell
    out (`generate`, `rake`, `rails_command`) to abort the generator if the
    command fails.

    *David Rodríguez*

186 187 188 189
*   Remove `app/assets` and `app/javascript` from `eager_load_paths` and `autoload_paths`.

    *Gannon McGibbon*

190 191
*   Use Ids instead of memory addresses when displaying references in scaffold views.

192 193 194 195
    Fixes #29200.

    *Rasesh Patel*

196 197 198 199 200
*   Adds support for multiple databases to `rails db:migrate:status`.
    Subtasks are also added to get the status of individual databases (eg. `rails db:migrate:status:animals`).

    *Gannon McGibbon*

201 202 203 204 205 206 207 208
*   Use Webpacker by default to manage app-level JavaScript through the new app/javascript directory.
    Sprockets is now solely in charge, by default, of compiling CSS and other static assets.
    Action Cable channel generators will create ES6 stubs rather than use CoffeeScript.
    Active Storage, Action Cable, Turbolinks, and Rails-UJS are loaded by a new application.js pack.
    Generators no longer generate JavaScript stubs.

    *DHH*, *Lachlan Sylvester*

209 210 211
*   Add `database` (aliased as `db`) option to model generator to allow
    setting the database. This is useful for applications that use
    multiple databases and put migrations per database in their own directories.
212 213

    ```
214
    bin/rails g model Room capacity:integer --database=kingston
215 216 217 218 219
          invoke  active_record
          create    db/kingston_migrate/20180830151055_create_rooms.rb
    ```

    Because rails scaffolding uses the model generator, you can
220
    also specify a database with the scaffold generator.
221 222 223

    *Gannon McGibbon*

224
*   Raise an error when "recyclable cache keys" are being used by a cache store
225 226 227
    that does not explicitly support it. Custom cache keys that do support this feature
    can bypass this error by implementing the `supports_cache_versioning?` method on their
    class and returning a truthy value.
228 229 230

    *Richard Schneeman*

231
*   Support environment specific credentials overrides.
232

233 234 235 236 237 238
    So any environment will look for `config/credentials/#{Rails.env}.yml.enc` and fall back
    to `config/credentials.yml.enc`.

    The encryption key can be in `ENV["RAILS_MASTER_KEY"]` or `config/credentials/production.key`.

    Environment credentials overrides can be edited with `rails credentials:edit --environment production`.
239
    If no override is set up for the passed environment, it will be created.
240 241

    Additionally, the default lookup paths can be overwritten with these configs:
242

243 244
    - `config.credentials.content_path`
    - `config.credentials.key_path`
245 246 247

    *Wojciech Wnętrzak*

248
*   Make `ActiveSupport::Cache::NullStore` the default cache store in the test environment.
249 250 251

    *Michael C. Nelson*

252 253 254 255
*   Emit warning for unknown inflection rule when generating model.

    *Yoshiyuki Kinjo*

256
*   Add `database` (aliased as `db`) option to migration generator.
257 258 259

    If you're using multiple databases and have a folder for each database
    for migrations (ex db/migrate and db/new_db_migrate) you can now pass the
260
    `--database` option to the generator to make sure the the migration
261 262 263
    is inserted into the correct folder.

    ```
264
    rails g migration CreateHouses --database=kingston
265 266 267 268 269 270
      invoke  active_record
      create    db/kingston_migrate/20180830151055_create_houses.rb
    ```

    *Eileen M. Uchitelle*

271 272 273 274
*   Deprecate `rake routes` in favor of `rails routes`.

    *Yuji Yaginuma*

275 276 277 278
*   Deprecate `rake initializers` in favor of `rails initializers`.

    *Annie-Claude Côté*

279 280 281 282
*   Deprecate `rake dev:cache` in favor of `rails dev:cache`.

    *Annie-Claude Côté*

283 284 285
*   Deprecate `rails notes` subcommands in favor of passing an `annotations` argument to `rails notes`.

    The following subcommands are replaced by passing `--annotations` or `-a` to `rails notes`:
286 287 288 289
    - `rails notes:custom ANNOTATION=custom` is deprecated in favor of using `rails notes -a custom`.
    - `rails notes:optimize` is deprecated in favor of using `rails notes -a OPTIMIZE`.
    - `rails notes:todo` is deprecated in favor of  using`rails notes -a TODO`.
    - `rails notes:fixme` is deprecated in favor of using `rails notes -a FIXME`.
290 291 292 293 294 295 296 297 298 299 300 301

    *Annie-Claude Côté*

*   Deprecate `SOURCE_ANNOTATION_DIRECTORIES` environment variable used by `rails notes`
    through `Rails::SourceAnnotationExtractor::Annotation` in favor of using `config.annotations.register_directories`.

    *Annie-Claude Côté*

*   Deprecate `rake notes` in favor of `rails notes`.

    *Annie-Claude Côté*

R
Ryuta Kamizono 已提交
302
*   Don't generate unused files in `app:update` task.
303

R
Ryuta Kamizono 已提交
304
    Skip the assets' initializer when sprockets isn't loaded.
305

R
Ryuta Kamizono 已提交
306
    Skip `config/spring.rb` when spring isn't loaded.
307

R
Ryuta Kamizono 已提交
308
    Skip yarn's contents when yarn integration isn't used.
309

310 311
    *Tsukuru Tanimichi*

312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328
*   Make the master.key file read-only for the owner upon generation on
    POSIX-compliant systems.

    Previously:

        $ ls -l config/master.key
        -rw-r--r--   1 owner  group      32 Jan 1 00:00 master.key

    Now:

        $ ls -l config/master.key
        -rw-------   1 owner  group      32 Jan 1 00:00 master.key

    Fixes #32604.

    *Jose Luis Duran*

329
*   Deprecate support for using the `HOST` environment variable to specify the server IP.
330

331
    The `BINDING` environment variable should be used instead.
332 333 334 335 336

    Fixes #29516.

    *Yuji Yaginuma*

337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354
*   Deprecate passing Rack server name as a regular argument to `rails server`.

    Previously:

        $ bin/rails server thin

    There wasn't an explicit option for the Rack server to use, now we have the
    `--using` option with the `-u` short switch.

    Now:

        $ bin/rails server -u thin

    This change also improves the error message if a missing or mistyped rack
    server is given.

    *Genadi Samokovarov*

355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373
*   Add "rails routes --expanded" option to output routes in expanded mode like
    "psql --expanded". Result looks like:

    ```
    $ rails routes --expanded
    --[ Route 1 ]------------------------------------------------------------
    Prefix            | high_scores
    Verb              | GET
    URI               | /high_scores(.:format)
    Controller#Action | high_scores#index
    --[ Route 2 ]------------------------------------------------------------
    Prefix            | new_high_score
    Verb              | GET
    URI               | /high_scores/new(.:format)
    Controller#Action | high_scores#new
    ```

    *Benoit Tigeot*

K
Kasper Timm Hansen 已提交
374
*   Rails 6 requires Ruby 2.5.0 or newer.
J
Jeremy Daer 已提交
375

K
Kasper Timm Hansen 已提交
376
    *Jeremy Daer*, *Kasper Timm Hansen*
J
Jeremy Daer 已提交
377 378


379
Please check [5-2-stable](https://github.com/rails/rails/blob/5-2-stable/railties/CHANGELOG.md) for previous changes.