CHANGELOG.md 6.7 KB
Newer Older
E
eileencodes 已提交
1 2
## Rails 6.0.0.beta3 (March 11, 2019) ##

3 4
*   Only accept formats from registered mime types

S
Shailesh Kalamkar 已提交
5
    A lack of filtering on mime types could allow an attacker to read
6 7 8 9 10 11 12
    arbitrary files on the target server or to perform a denial of service
    attack.

    Fixes CVE-2019-5418
    Fixes CVE-2019-5419

    *John Hawthorn*, *Eileen M. Uchitelle*, *Aaron Patterson*
E
eileencodes 已提交
13 14


15 16
## Rails 6.0.0.beta2 (February 25, 2019) ##

17 18 19
*   ActionView::Template.finalize_compiled_template_methods is deprecated with
    no replacement.

A
Aaron Patterson 已提交
20 21
    *tenderlove*

22 23 24
*   config.action_view.finalize_compiled_template_methods is deprecated with
    no replacement.

A
Aaron Patterson 已提交
25 26
    *tenderlove*

27 28 29 30 31
*   Ensure unique DOM IDs for collection inputs with float values.
    Fixes #34974

    *Mark Edmondson*

G
Gannon McGibbon 已提交
32

33 34
## Rails 6.0.0.beta1 (January 18, 2019) ##

35 36 37 38 39 40
*   [Rename npm package](https://github.com/rails/rails/pull/34905) from
    [`rails-ujs`](https://www.npmjs.com/package/rails-ujs) to
    [`@rails/ujs`](https://www.npmjs.com/package/@rails/ujs).

    *Javan Makhmali*

41 42 43 44
*   Remove deprecated `image_alt` helper.

    *Rafael Mendonça França*

45 46 47 48 49
*   Fix the need of `#protect_against_forgery?` method defined in
    `ActionView::Base` subclasses. This prevents the use of forms and buttons.

    *Genadi Samokovarov*

W
WoH 已提交
50
*   Fix UJS permanently showing disabled text in a[data-remote][data-disable-with] elements within forms.
51 52

    Fixes #33889.
W
WoH 已提交
53 54 55

    *Wolfgang Hobmaier*

56 57 58 59 60 61 62 63
*   Prevent non-primary mouse keys from triggering Rails UJS click handlers.
    Firefox fires click events even if the click was triggered by non-primary mouse keys such as right- or scroll-wheel-clicks.
    For example, right-clicking a link such as the one described below (with an underlying ajax request registered on click) should not cause that request to occur.

    ```
    <%= link_to 'Remote', remote_path, class: 'remote', remote: true, data: { type: :json } %>
    ```

64
    Fixes #34541.
65 66 67

    *Wolfgang Hobmaier*

68 69 70 71 72 73 74 75 76 77 78 79 80
*   Prevent `ActionView::TextHelper#word_wrap` from unexpectedly stripping white space from the _left_ side of lines.

    For example, given input like this:

    ```
        This is a paragraph with an initial indent,
    followed by additional lines that are not indented,
    and finally terminated with a blockquote:
      "A pithy saying"
    ```

    Calling `word_wrap` should not trim the indents on the first and last lines.

81
    Fixes #34487.
82 83 84

    *Lyle Mullican*

85 86 87 88 89 90 91 92 93 94 95 96
*   Add allocations to template rendering instrumentation.

    Adds the allocations for template and partial rendering to the server output on render.

    ```
      Rendered posts/_form.html.erb (Duration: 7.1ms | Allocations: 6004)
      Rendered posts/new.html.erb within layouts/application (Duration: 8.3ms | Allocations: 6654)
    Completed 200 OK in 858ms (Views: 848.4ms | ActiveRecord: 0.4ms | Allocations: 1539564)
    ```

    *Eileen M. Uchitelle*, *Aaron Patterson*

97
*   Respect the `only_path` option passed to `url_for` when the options are passed in as an array
98

99 100 101 102
    Fixes #33237.

    *Joel Ambass*

103
*   Deprecate calling private model methods from view helpers.
104

105 106 107
    For example, in methods like `options_from_collection_for_select`
    and `collection_select` it is possible to call private methods from
    the objects used.
108

109
    Fixes #33546.
110

111
    *Ana María Martínez Gómez*
112

113 114 115 116 117 118 119 120 121 122 123
*   Fix issue with `button_to`'s `to_form_params`

    `button_to` was throwing exception when invoked with `params` hash that
    contains symbol and string keys. The reason for the exception was that
    `to_form_params` was comparing the given symbol and string keys.

    The issue is fixed by turning all keys to strings inside
    `to_form_params` before comparing them.

    *Georgi Georgiev*

124 125 126
*   Mark arrays of translations as trusted safe by using the `_html` suffix.

    Example:
127 128 129 130 131 132 133 134 135

        en:
          foo_html:
            - "One"
            - "<strong>Two</strong>"
            - "Three &#128075; &#128578;"

    *Juan Broullon*

136
*   Add `year_format` option to date_select tag. This option makes it possible to customize year
137 138 139
    names. Lambda should be passed to use this option.

    Example:
140 141 142

        date_select('user_birthday', '', start_year: 1998, end_year: 2000, year_format: ->year { "Heisei #{year - 1988}" })

143
    The HTML produced:
144 145 146 147 148 149 150 151 152 153

        <select id="user_birthday__1i" name="user_birthday[(1i)]">
        <option value="1998">Heisei 10</option>
        <option value="1999">Heisei 11</option>
        <option value="2000">Heisei 12</option>
        </select>
        /* The rest is omitted */

    *Koki Ryu*

154 155 156 157 158 159 160
*   Fix JavaScript views rendering does not work with Firefox when using
    Content Security Policy.

    Fixes #32577.

    *Yuji Yaginuma*

161 162 163 164 165 166
*   Add the `nonce: true` option for `javascript_include_tag` helper to
    support automatic nonce generation for Content Security Policy.
    Works the same way as `javascript_tag nonce: true` does.

    *Yaroslav Markin*

B
bogdanvlviv 已提交
167
*   Remove `ActionView::Helpers::RecordTagHelper`.
Y
Yoshiyuki Hirano 已提交
168 169 170

    *Yoshiyuki Hirano*

B
bogdanvlviv 已提交
171
*   Disable `ActionView::Template` finalizers in test environment.
172 173 174 175 176 177 178 179

    Template finalization can be expensive in large view test suites.
    Add a configuration option,
    `action_view.finalize_compiled_template_methods`, and turn it off in
    the test environment.

    *Simon Coffey*

180
*   Extract the `confirm` call in its own, overridable method in `rails_ujs`.
R
Ryuta Kamizono 已提交
181 182 183

    Example:

184 185 186 187 188 189
        Rails.confirm = function(message, element) {
          return (my_bootstrap_modal_confirm(message));
        }

    *Mathieu Mahé*

190
*   Enable select tag helper to mark `prompt` option as `selected` and/or `disabled` for `required`
R
Ryuta Kamizono 已提交
191 192 193
    field.

    Example:
194

B
bogdanvlviv 已提交
195 196 197 198
        select :post,
               :category,
               ["lifestyle", "programming", "spiritual"],
               { selected: "", disabled: "", prompt: "Choose one" },
199
               { required: true }
200

R
Ryuta Kamizono 已提交
201 202 203
    Placeholder option would be selected and disabled.

    The HTML produced:
204

205 206 207 208 209 210 211 212
        <select required="required" name="post[category]" id="post_category">
        <option disabled="disabled" selected="selected" value="">Choose one</option>
        <option value="lifestyle">lifestyle</option>
        <option value="programming">programming</option>
        <option value="spiritual">spiritual</option></select>

    *Sergey Prikhodko*

B
bogdanvlviv 已提交
213
*   Don't enforce UTF-8 by default.
A
Andrew White 已提交
214 215 216 217 218 219 220

    With the disabling of TLS 1.0 by most major websites, continuing to run
    IE8 or lower becomes increasingly difficult so default to not enforcing
    UTF-8 encoding as it's not relevant to other browsers.

    *Andrew White*

221 222 223 224
*   Change translation key of `submit_tag` from `module_name_class_name` to `module_name/class_name`.

    *Rui Onodera*

K
Kasper Timm Hansen 已提交
225
*   Rails 6 requires Ruby 2.5.0 or newer.
J
Jeremy Daer 已提交
226

K
Kasper Timm Hansen 已提交
227
    *Jeremy Daer*, *Kasper Timm Hansen*
228 229


230
Please check [5-2-stable](https://github.com/rails/rails/blob/5-2-stable/actionview/CHANGELOG.md) for previous changes.