Repository navigation
Releases: rails/rails
Release list
8.1.4
Active Support
-
Fix the debug error page rendering for
SyntaxErrors with multi-line messages.Marco Roth
-
Make
ActiveSupport::JSON.decodecompatible with the upcomingjson3.0 gem.Earlopain
-
Fix
number_to_human_sizecrashing for sizes above a terabyte by supporting
petabyte, exabyte, and zettabyte storage units.Kenta Ishizaki
-
Fix
Range#soleraisingNoMethodErrorwhen the enumerable core extension
isn't already loaded.Kenta Ishizaki
-
Fix
ActiveSupport::Cache::FileStoreraisingNameErrorforFileUtils
whenfileutilsisn't already loaded.Kenta Ishizaki
-
Fix
Enumerable#in_order_ofwithfilter: truedroppingnilelements
explicitly named in the series.Kenta Ishizaki
-
Keep
HashWithIndifferentAccess#filterreturning aHashWithIndifferentAccess
instead of a plainHash.Kenta Ishizaki
-
Fix
number_to_humanandnumber_to_human_sizecrashing when:precisionisnil.Kenta Ishizaki
-
Fix
ActiveSupport::InheritableOptions#to_hto recursively flatten nested
InheritableOptionsparents.Andrew Novoselac
-
Fix
ActiveSupport::StructuredEventSubscriber.debug_onlyleaking debug-only
methods across subscriber subclasses.Kenta Ishizaki
-
Fix
ActiveSupport::Inflector#transliteratemutating the caller's string.Kenta Ishizaki
-
Fix
Hash.from_xmlraisingDate::Errorontype="date"values surrounded
by whitespace.Kenta Ishizaki
-
Fix
Time#advanceandDateTime#advancemutating the options hash passed
by the caller.Kenta Ishizaki
-
Fix
ActiveSupport::Cache::MemoryStore#cleanupraisingNoMethodErrorwhen
used with a non-DupCoderserializer.Kenta Ishizaki
-
Fix
String#truncatewith:separatormisbehaving when the:omissionis
longer than the target length.Kenta Ishizaki
-
Fix
ActiveSupport::Cache::Store#delete_multimutating the names array passed
by the caller.Kenta Ishizaki
-
Fix
number_to_currencycrashing on a negative number when:precisionisnil.Kenta Ishizaki
-
Fix
TimeZone#strptimewith%sdropping the sub-second fraction of the timestamp.Kenta Ishizaki
-
Fix
HashWithIndifferentAccess.newdropping a falsy (falseor0) default
value from the source hash.Kenta Ishizaki
-
Fix
Range#include?andRange#===raising on exclusive non-integer sub-ranges.Kenta Ishizaki
-
Fix
number_to_delimitedcorrupting numbers that begin with a+or-sign.Kenta Ishizaki
-
Fix
ActiveSupport::InheritableOptions#==raisingNoMethodErrorwhen compared
with a non-Hash object.Kenta Ishizaki
-
Fix
Enumerable#in_order_ofwithfilter: falsedropping elements whose keyed
value isnil.Hammad Khan
-
Stop the DRb service when shutting down parallel test workers, preventing it
from lingering after the test run.Shuta Mugikura
-
Preserve the encoding of
ActiveSupport::SafeBuffervalues round-tripped through
ActiveSupport::MessagePack.Rafael MendonΓ§a FranΓ§a
-
Fix
number_to_phonewithout an area code stripping a leading delimiter when the
number itself coincidentally starts with the delimiter string.Tahsin Hasan
-
Update
ActiveSupport::TimeZonemappings to use the current IANA identifiers
Europe/Kyiv(wasEurope/Kiev) andAsia/Yangon(wasAsia/Rangoon).tsymbalenkovlad
-
Use the faster string-based delimiter logic by default in
number_to_delimited,
instead of the regular expression fallback.Shinichi Maeshima
-
Preserve the requested key order in
ActiveSupport::Cache::Store#fetch_multi
when a local cache is active.Previously, if some keys were served from the local cache and others from the
underlying store,fetch_multireturned the local cache hits first instead of
following the order of the requested keys.Mueez Afzal
-
Fix
String#parameterizeraisingTypeErrorwhenseparatorisnil.parameterizealready treats anilseparator the same as an empty one when
squeezing and trimming separators, but raisedTypeErrorbefore reaching that
point. Anilseparator now behaves like"", removing the unwanted characters."Donald E. Knuth".parameterize(separator: nil) # => "donaldeknuth"
Hammad Khan
-
Add
RedisClient::ErrortoActiveSupport::Cache::RedisCacheStore's failsafe rescue list.The redis-rb gem normally translates
RedisClient::*errors intoRedis::*errors but in
some rare cases, such as when using sentinels,RedisClient::*errors may slip through.David Arrunategui
-
Fix
ActiveSupport::Duration#in_minutes,#in_hours,#in_days,
#in_weeks,#in_months, and#in_yearstruncating sub-second precision.These methods divided the duration's integer second count (
in_seconds,
aliased toto_i) instead of its exact value, so any fractional second was
silently dropped before the conversion.# Before 90.5.seconds.in_minutes # => 1.5 # After 90.5.seconds.in_minutes # => 1.5083333333333333
Kenta Ishizaki
-
Fix JSON encoding of non-String Hash keys.
The old encoder would simply call
to_son them, the newer encoder
would incorrectly callas_jsoninstead.In the case of
Time,DateTimeandTimeWithZonethis would result
in different serialization of time keys:"2009-01-01T12:30:00.000Z"(arguably better)
instead of"2009-01-01 12:30:00 UTC"(how it used to be).Kenta Ishizaki
-
Fix
number_to_phonedropping only the first character of a
multi-character:delimiterwhen no area code is present.The leading delimiter produced by an empty first capture group was
stripped withslice!(0, 1), which assumed a single-character
delimiter. Multi-character (and multibyte) delimiters now work:number_to_phone(5551234, delimiter: " - ") # => "555 - 1234" # was "- 555 - 1234"Kenta Ishizaki
-
Fix
titleizeinflector to consider Unicode characters"Δasim Δipa".titleize # => "Δasim Δipa"
Eldin Guzin
Active Model
-
Fix
ActiveModel::Errors#importmutating the override options hash passed to it.Kenta Ishizaki
-
Fix
normalizesnot detecting in-place changes for attributes whose database
cast type differs from the attribute type (e.g. JSON columns), causing
normalization to be skipped on validation.Chedli Bourguiba
-
Fix
alias_attributeaccumulating duplicate entries inaliases_by_attribute_name
when called multiple times with the same arguments.Nicholas Jakobsen
-
Fix
normalizesre-applying normalizations on every validation of an
unpersisted record, and speed up validation of normalized attributes.The in-place mutation check re-ran the normalizer on every
valid?of an
unpersisted record: wasteful for idempotent normalizers and compounded the
result for non-idempotent ones. Normalizations are now re-applied only on a
genuine in-place mutation.Yaroslav Markin
-
Limit the size of strings
ActiveModel::Type::Integerwill coerce withto_i.Calling
to_ion very long strings can take a long time and could be used as
a DoS vector. Integer casting now only considers the first_limit * 4bytes
of a string (16 bytes for a default 4-byte integer, 32 bytes for an 8-byte
bigint), which is enough to hold the maximum representable value plus a sign
or a short slug suffix.Aaron Patterson, Jean Boussier
Active Record
-
Avoid deadlocks when concurrent
find_or_create_bycalls read back the same
record within MySQL transactions.Use a shared lock for the read after a duplicate insert, preserving visibility
under REPEATABLE READ without upgrading competing shared locks to exclusive locks.
This also applies tocreate_or_find_byand the bang variants of both methods.Fixes #54281.
Kirsten Westeinde
-
Filter the database password out of failed
db:task command error messages.Ngan Pham
-
Fix
ActiveRecord::TypeCaster::Connectionsometimes leaking a checked-out
connection.Hartley McGuire
-
Fix PostgreSQL exclusion constraints with multiline expressions being parsed
incorrectly during schema introspection.Jake McAllister
-
Fix async
ActiveRecord::StatementCache#executeraising an error for
out-of-range bind values instead of returning an empty result.viralpraxis
-
Fix
whereclauses with column-tuple syntax not resolving references to
other tables.Chris Gunther
-
Fix
distinct: truebeing ignored byaverage.Kenta Ishizaki
-
Fix
belongs_tochange tracking for composite foreign keys.Only the first foreign key column was checked for changes; now all foreign
key columns are checked.Anas Khan
-
Make
add_column(if_not_exists: true)reversible.Kenta Ishizaki
-
Quote the index name in MySQL
enable_indexanddisable_index.Unquoted index names containing special characters could cause SQL syntax
errors.Kenta Ishizaki
-
Make
remove_foreign_key(if_exists: true)reversible.Kenta Ishizaki
-
Fix
distinct: truebeing ignored by groupedsum.Kenta Ishizaki
-
Return an
ActiveRecord::Promisefromasync_idson a contradictory
relation, instead ...
7.2.4
Active Support
-
Improve
number_to_delimitedperformance whendelimiter_patternis not specified.Shinichi Maeshima
-
Silence Dalli 4.0+ warning when using
ActiveSupport::Cache::MemCacheStore.zzak
-
Fix
ActiveSupport::Inflector.humanizewith international characters.ActiveSupport::Inflector.humanize("Γ‘ΓΓΓΓ") # => "ΓΓ©ΓΓ³ΓΊ" ActiveSupport::Inflector.humanize("Π°ΠΠΠΠΠ") # => "ΠΠ±Π²Π³Π΄Π΅"
Jose Luis Duran
Active Model
- No changes.
Active Record
-
Fix performance regression in
method_missingfor virtual SELECT alias
attributes.Fixes #57183.
Hammad Khan
-
Fix support for table names containing hyphens.
Evgeniy Demin
-
Improve PostgreSQLAdapter resilience to Timeout.timeout.
Better handle asynchronous exceptions being thrown inside
thereconnect!method.This may fixes some deep errors such as:
undefined method `key?' for nil:NilClass (NoMethodError) if !type_map.key?(oid)Jean Boussier
-
Fix
eager_loadwhen loadinghas_manyassocations with composite primary keys.This would result in some records being loaded multiple times.
Martin-Alexander
Action View
-
Fix strict locals parsing to handle multiline definitions.
Said Kaldybaev
Action Pack
-
Fix
ActionController::UnknownHttpMethodto return405 Method Not Allowed
instead of500 Internal Server Error.Nicolas Vandenbogaerde
Active Job
- No changes.
Action Mailer
- No changes.
Action Cable
- No changes.
Active Storage
- No changes.
Action Mailbox
- No changes.
Action Text
- No changes.
Railties
-
Fixed the default Dockerfile to properly include the
vendor/directory duringbundle install.Zhong Sheng
Guides
- No changes.
8.1.3.1
Active Support
- No changes.
Active Model
- No changes.
Active Record
- No changes.
Action View
- No changes.
Action Pack
- No changes.
Active Job
- No changes.
Action Mailer
- No changes.
Action Cable
- No changes.
Active Storage
-
Disable libvips's unfuzzed image loaders and savers.
libvips flags some of its loaders and savers as "unfuzzed" or "untrusted", meaning they are only
safe for trusted content. Active Storage will callVips.block_untrusted(true)to disable them
while booting. An application that needs a specific loader or saver may re-enable it in an
initializer.This is a breaking change for applications that process image types with an unfuzzed loader or
saver. Variant transformation of BMP, ICO, and PSD attachments will raiseVips::Error, and
analysis of these and other types such as SVG, JPEG XL, JPEG 2000, and Netpbm will no longer
recordwidthandheight. Requesting an unfuzzed output format, typically FITS, JXL, or
anything delegated to ImageMagick, will also raiseVips::Error. Attaching, storing, and
downloading are unchanged.An application seeing
Vips::Errorraised during image transformation may wish to remove the
affected content types fromconfig.active_storage.variable_content_typesin an initializer.
Active Storage will then treat those attachments as not variable and will not generate variants
for them. This most often matters to an application that transforms images during a request
rather than in a background job, where the failure surfaces as an error response instead of a
failed job.Rails.application.config.active_storage.variable_content_types -= %w[ image/bmp image/vnd.microsoft.icon image/vnd.adobe.photoshop ]
Applications using the
:mini_magickvariant processor will see no change in how their
attachments are processed, but the loaders and savers will be disabled process-wide whenever
ruby-vips is installed, and the version requirements below will still apply. Such an application
may remove ruby-vips from its Gemfile to avoid both.The minimum supported version of libvips is now 8.13, and the minimum supported version of
ruby-vips is now 2.2.1. These are the earliest versions that are capable of disabling untrusted
operations. When ruby-vips is installed and either minimum is not met, Active Storage will raise
aRuntimeErrorwhile booting rather than run in an unsecurable environment.[GHSA-xr9x-r78c-5hrm]
[CVE-2026-66066]Mike Dalessio
Action Mailbox
- No changes.
Action Text
- No changes.
Railties
- No changes.
Guides
- No changes.
8.0.5.1
Active Support
- No changes.
Active Model
- No changes.
Active Record
- No changes.
Action View
- No changes.
Action Pack
- No changes.
Active Job
- No changes.
Action Mailer
- No changes.
Action Cable
- No changes.
Active Storage
-
Disable libvips's unfuzzed image loaders and savers.
libvips flags some of its loaders and savers as "unfuzzed" or "untrusted", meaning they are only
safe for trusted content. Active Storage will callVips.block_untrusted(true)to disable them
while booting. An application that needs a specific loader or saver may re-enable it in an
initializer.This is a breaking change for applications that process image types with an unfuzzed loader or
saver. Variant transformation of BMP, ICO, and PSD attachments will raiseVips::Error, and
analysis of these and other types such as SVG, JPEG XL, JPEG 2000, and Netpbm will no longer
recordwidthandheight. Requesting an unfuzzed output format, typically FITS, JXL, or
anything delegated to ImageMagick, will also raiseVips::Error. Attaching, storing, and
downloading are unchanged.An application seeing
Vips::Errorraised during image transformation may wish to remove the
affected content types fromconfig.active_storage.variable_content_typesin an initializer.
Active Storage will then treat those attachments as not variable and will not generate variants
for them. This most often matters to an application that transforms images during a request
rather than in a background job, where the failure surfaces as an error response instead of a
failed job.Rails.application.config.active_storage.variable_content_types -= %w[ image/bmp image/vnd.microsoft.icon image/vnd.adobe.photoshop ]
Applications using the
:mini_magickvariant processor will see no change in how their
attachments are processed, but the loaders and savers will be disabled process-wide whenever
ruby-vips is installed, and the version requirements below will still apply. Such an application
may remove ruby-vips from its Gemfile to avoid both.The minimum supported version of libvips is now 8.13, and the minimum supported version of
ruby-vips is now 2.2.1. These are the earliest versions that are capable of disabling untrusted
operations. When ruby-vips is installed and either minimum is not met, Active Storage will raise
aRuntimeErrorwhile booting rather than run in an unsecurable environment.[GHSA-xr9x-r78c-5hrm]
[CVE-2026-66066]Mike Dalessio
Action Mailbox
- No changes.
Action Text
- No changes.
Railties
- No changes.
Guides
- No changes.
7.2.3.2
Active Support
- No changes.
Active Model
- No changes.
Active Record
- No changes.
Action View
- No changes.
Action Pack
- No changes.
Active Job
- No changes.
Action Mailer
- No changes.
Action Cable
- No changes.
Active Storage
-
Disable libvips's unfuzzed image loaders and savers.
libvips flags some of its loaders and savers as "unfuzzed" or "untrusted", meaning they are only
safe for trusted content. Active Storage will callVips.block_untrusted(true)to disable them
while booting. An application that needs a specific loader or saver may re-enable it in an
initializer.This is a breaking change for applications that process image types with an unfuzzed loader or
saver. Variant transformation of BMP, ICO, and PSD attachments will raiseVips::Error, and
analysis of these and other types such as SVG, JPEG XL, JPEG 2000, and Netpbm will no longer
recordwidthandheight. Requesting an unfuzzed output format, typically FITS, JXL, or
anything delegated to ImageMagick, will also raiseVips::Error. Attaching, storing, and
downloading are unchanged.An application seeing
Vips::Errorraised during image transformation may wish to remove the
affected content types fromconfig.active_storage.variable_content_typesin an initializer.
Active Storage will then treat those attachments as not variable and will not generate variants
for them. This most often matters to an application that transforms images during a request
rather than in a background job, where the failure surfaces as an error response instead of a
failed job.Rails.application.config.active_storage.variable_content_types -= %w[ image/bmp image/vnd.microsoft.icon image/vnd.adobe.photoshop ]
Applications using the
:mini_magickvariant processor will see no change in how their
attachments are processed, but the loaders and savers will be disabled process-wide whenever
ruby-vips is installed, and the version requirements below will still apply. Such an application
may remove ruby-vips from its Gemfile to avoid both.The minimum supported version of libvips is now 8.13, and the minimum supported version of
ruby-vips is now 2.2.1. These are the earliest versions that are capable of disabling untrusted
operations. When ruby-vips is installed and either minimum is not met, Active Storage will raise
aRuntimeErrorwhile booting rather than run in an unsecurable environment.[GHSA-xr9x-r78c-5hrm]
[CVE-2026-66066]Mike Dalessio
Action Mailbox
- No changes.
Action Text
- No changes.
Railties
- No changes.
Guides
- No changes.
8.1.3
Active Support
-
Fix
JSONGemCoderEncoderto correctly serialize custom object hash keys.When hash keys are custom objects whose
as_jsonreturns a Hash,
the encoder now callsto_son the original key object instead of
on theas_jsonresult.Before:
hash = {CustomKey.new(123) => "value"}
hash.to_json # => {"{:id=>123}":"value"}After:
hash.to_json # => {"custom_123":"value"}Dan Sharp
-
Fix inflections to better handle overlapping acronyms.
ActiveSupport::Inflector.inflections(:en) do |inflect| inflect.acronym "USD" inflect.acronym "USDC" end "USDC".underscore # => "usdc"
Said Kaldybaev
-
Silence Dalli 4.0+ warning when using
ActiveSupport::Cache::MemCacheStore.zzak
Active Model
-
Fix Ruby 4.0 delegator warning when calling inspect on attributes.
Hammad Khan
-
Fix
NoMethodErrorwhen deserialisingType::Integerobjects marshalled under Rails 8.0.The performance optimisation that replaced
@rangewith@max/@min
broke Marshal compatibility. Objects serialised under 8.0 (with@range)
and deserialised under 8.1 (expecting@max/@min) would crash with
undefined method '<=' for nilbecauseMarshal.loadrestores instance
variables without callinginitialize.Edward Woodcock
Active Record
-
Fix
insert_allandupsert_alllog message when called on anonymous classes.Gabriel Sobrinho
-
Respect
ActiveRecord::SchemaDumper.ignore_tableswhen dumping SQLite virtual tables.Hans Schnedlitz
-
Restore previous instrumenter after
execute_or_skipFutureResult#execute_or_skipreplaces the thread's instrumenter with an
EventBufferto collect events published during async query execution.
If the global async executor is saturated and thecaller_runsfallback
executes the task on the calling thread, we need to make sure the previous
instrumenter is restored or the staleEventBufferwould stay in place and
permanently swallow all subsequentsql.active_recordnotifications on
that thread.Rosa Gutierrez
-
Bump the minimum PostgreSQL version to 9.5, due to usage of
array_positionfunction.Ivan Kuchin
-
Fix Ruby 4.0 delegator warning when calling inspect on ActiveRecord::Type::Serialized.
Hammad Khan
-
Fix support for table names containing hyphens.
Evgeniy Demin
-
Fix column deduplication for SQLite3 and PostgreSQL virtual (generated) columns.
Column#==andColumn#hashnow account forvirtual?so that the
Deduplicableregistry does not treat a generated column and a regular
column with the same name and type as identical. Previously, if a
generated column was registered first, a regular column on a different
table could be deduplicated to the generated instance, silently
excluding it from INSERT/UPDATE statements.Jay Huber
-
Fix PostgreSQL schema dumping to handle schema-qualified table names in foreign_key references that span different schemas.
# before add_foreign_key "hst.event_log_attributes", "hst.event_logs" # emits correctly because they're in the same schema (hst) add_foreign_key "hst.event_log_attributes", "hst.usr.user_profiles", column: "created_by_id" # emits hst.user.* when user.* is expected # after add_foreign_key "hst.event_log_attributes", "hst.event_logs" add_foreign_key "hst.event_log_attributes", "usr.user_profiles", column: "created_by_id"Chiperific
Action View
-
Fix encoding errors for string locals containing non-ASCII characters.
Kataoka Katsuki
-
Fix collection caching to only forward
expires_inargument if explicitly set.Pieter Visser
Action Pack
- No changes.
Active Job
- No changes.
Action Mailer
- No changes.
Action Cable
- No changes.
Active Storage
-
Fix
ActiveStorage::Blobcontent type predicate methods to handlenil.Daichi KUDO
Action Mailbox
- No changes.
Action Text
- No changes.
Railties
-
Add
libvipsto generatedci.ymlConditionally adds
libvipstoci.yml.Steve Polito
Guides
- No changes.
8.0.5
Active Support
-
Fix inflections to better handle overlapping acronyms.
ActiveSupport::Inflector.inflections(:en) do |inflect| inflect.acronym "USD" inflect.acronym "USDC" end "USDC".underscore # => "usdc"
Said Kaldybaev
-
Silence Dalli 4.0+ warning when using
ActiveSupport::Cache::MemCacheStore.zzak
-
Make
delegateanddelegate_missing_towork in BasicObject subclasses.Rafael MendonΓ§a FranΓ§a
-
Fix
ActiveSupport::Inflector.humanizewith international characters.ActiveSupport::Inflector.humanize("Γ‘ΓΓΓΓ") # => "ΓΓ©ΓΓ³ΓΊ" ActiveSupport::Inflector.humanize("Π°ΠΠΠΠΠ") # => "ΠΠ±Π²Π³Π΄Π΅"
Jose Luis Duran
Active Model
- No changes.
Active Record
-
Fix
insert_allandupsert_alllog message when called on anonymous classes.Gabriel Sobrinho
-
Respect
ActiveRecord::SchemaDumper.ignore_tableswhen dumping SQLite virtual tables.Hans Schnedlitz
-
Restore previous instrumenter after
execute_or_skipFutureResult#execute_or_skipreplaces the thread's instrumenter with an
EventBufferto collect events published during async query execution.
If the global async executor is saturated and thecaller_runsfallback
executes the task on the calling thread, we need to make sure the previous
instrumenter is restored or the staleEventBufferwould stay in place and
permanently swallow all subsequentsql.active_recordnotifications on
that thread.Rosa Gutierrez
-
Fix Ruby 4.0 delegator warning when calling inspect on ActiveRecord::Type::Serialized.
Hammad Khan
-
Fix support for table names containing hyphens.
Evgeniy Demin
-
Fix column deduplication for SQLite3 and PostgreSQL virtual (generated) columns.
Column#==andColumn#hashnow account forvirtual?so that the
Deduplicableregistry does not treat a generated column and a regular
column with the same name and type as identical. Previously, if a
generated column was registered first, a regular column on a different
table could be deduplicated to the generated instance, silently
excluding it from INSERT/UPDATE statements.Jay Huber
-
Fix merging relations with arel equality predicates with null relations.
fatkodima
-
Fix SQLite3 schema dump for non-autoincrement integer primary keys.
Previously,
schema.rbshould incorrectly restore that table with an auto incrementing
primary key.Chris HasiΕski
-
Fix PostgreSQL
schema_search_pathnot being reapplied afterreset!orreconnect!.The
schema_search_pathconfigured indatabase.ymlis now correctly
reapplied instead of falling back to PostgreSQL defaults.Tobias Egli
-
Ensure batched preloaded associations accounts for klass when grouping to avoid issues with STI.
zzak, Stjepan Hadjic
-
Fix
ActiveRecord::SoleRecordExceeded#recordto return the relation.This was the case until Rails 7.2, but starting from 8.0 it
started mistakenly returning the model class.Jean Boussier
-
Improve PostgreSQLAdapter resilience to Timeout.timeout.
Better handle asynchronous exceptions being thrown inside
thereconnect!method.This may fixes some deep errors such as:
undefined method `key?' for nil:NilClass (NoMethodError) if !type_map.key?(oid)Jean Boussier
-
Fix
eager_loadwhen loadinghas_manyassocations with composite primary keys.This would result in some records being loaded multiple times.
Martin-Alexander
Action View
-
Fix encoding errors for string locals containing non-ASCII characters.
Kataoka Katsuki
-
Fix collection caching to only forward
expires_inargument if explicitly set.Pieter Visser
-
Fix
file_fieldto join mime types with a comma when provided as Arrayfile_field(:article, :image, accept: ['image/png', 'image/gif', 'image/jpeg'])
Now behaves likes:
file_field(:article, :image, accept: 'image/png,image/gif,image/jpeg')Bogdan Gusiev
-
Fix strict locals parsing to handle multiline definitions.
Said Kaldybaev
Action Pack
-
Add
config.action_controller.live_streaming_excluded_keysto control execution state sharing in ActionController::Live.When using ActionController::Live, actions are executed in a separate thread that shares
state from the parent thread. This new configuration allows applications to opt-out specific
state keys that should not be shared.This is useful when streaming inside a
connected_toblock, where you may want
the streaming thread to use its own database connection context.# config/application.rb config.action_controller.live_streaming_excluded_keys = [:active_record_connected_to_stack]
By default, all keys are shared.
Eileen M. Uchitelle
Active Job
- No changes.
Action Mailer
- No changes.
Action Cable
- No changes.
Active Storage
-
Fix
ActiveStorage::Blobcontent type predicate methods to handlenil.Daichi KUDO
Action Mailbox
- No changes.
Action Text
- No changes.
Railties
-
Fixed the
rails notescommand to properly extract notes in CSS files.David White
-
Fixed the default Dockerfile to properly include the
vendor/directory duringbundle install.Zhong Sheng
Guides
- No changes.
8.1.2.1
Active Support
-
Reject scientific notation in NumberConverter
Jean Boussier
-
Fix
SafeBuffer#%to preserve unsafe statusJean Boussier
-
Improve performance of NumberToDelimitedConverter
Jean Boussier
Active Model
- No changes.
Active Record
- No changes.
Action View
-
Skip blank attribute names in tag helpers to avoid generating invalid HTML.
Mike Dalessio
Action Pack
-
Fix possible XSS in DebugExceptions middleware
John Hawthorn
Active Job
- No changes.
Action Mailer
- No changes.
Action Cable
- No changes.
Active Storage
-
Filter user supplied metadata in DirectUploadController
Jean Boussier
-
Configurable maxmimum streaming chunk size
Makes sure that byte ranges for blobs don't exceed 100mb by default.
Content ranges that are too big can result in denial of service.Gannon McGibbon
-
Limit range requests to a single range
Jean Boussier
-
Prevent path traversal in
DiskService.DiskService#path_fornow raises anInvalidKeyErrorwhen passed keys with dot segments (".",
".."), or if the resolved path is outside the storage root directory.#path_foralso now consistently raisesInvalidKeyErrorif the key is invalid in any way, for
example containing null bytes or having an incompatible encoding. Previously, the exception
raised may have beenArgumentErrororEncoding::CompatibilityError.DiskControllernow explicitly rescuesInvalidKeyErrorwith appropriate HTTP status codes.Mike Dalessio
-
Prevent glob injection in
DiskService#delete_prefixed.Escape glob metacharacters in the resolved path before passing to
Dir.glob.Note that this change breaks any existing code that is relying on
delete_prefixedto expand
glob metacharacters. This change presumes that is unintended behavior (as other storage services
do not respect these metacharacters).Mike Dalessio
Action Mailbox
- No changes.
Action Text
- No changes.
Railties
- No changes.
Guides
- No changes.
8.0.4.1
Active Support
-
Reject scientific notation in NumberConverter
Jean Boussier
-
Fix
SafeBuffer#%to preserve unsafe statusJean Boussier
-
Improve performance of NumberToDelimitedConverter
Jean Boussier
Active Model
- No changes.
Active Record
- No changes.
Action View
-
Skip blank attribute names in tag helpers to avoid generating invalid HTML.
Mike Dalessio
Action Pack
- No changes.
Active Job
- No changes.
Action Mailer
- No changes.
Action Cable
- No changes.
Active Storage
-
Filter user supplied metadata in DirectUploadController
Jean Boussier
-
Configurable maxmimum streaming chunk size
Makes sure that byte ranges for blobs don't exceed 100mb by default.
Content ranges that are too big can result in denial of service.Gannon McGibbon
-
Limit range requests to a single range
Jean Boussier
-
Prevent path traversal in
DiskService.DiskService#path_fornow raises anInvalidKeyErrorwhen passed keys with dot segments (".",
".."), or if the resolved path is outside the storage root directory.#path_foralso now consistently raisesInvalidKeyErrorif the key is invalid in any way, for
example containing null bytes or having an incompatible encoding. Previously, the exception
raised may have beenArgumentErrororEncoding::CompatibilityError.DiskControllernow explicitly rescuesInvalidKeyErrorwith appropriate HTTP status codes.Mike Dalessio
-
Prevent glob injection in
DiskService#delete_prefixed.Escape glob metacharacters in the resolved path before passing to
Dir.glob.Note that this change breaks any existing code that is relying on
delete_prefixedto expand
glob metacharacters. This change presumes that is unintended behavior (as other storage services
do not respect these metacharacters).Mike Dalessio
Action Mailbox
- No changes.
Action Text
- No changes.
Railties
- No changes.
Guides
- No changes.
7.2.3.1
Active Support
-
Reject scientific notation in NumberConverter
Jean Boussier
-
Fix
SafeBuffer#%to preserve unsafe statusJean Boussier
-
Improve performance of NumberToDelimitedConverter
Jean Boussier
Active Model
- No changes.
Active Record
- No changes.
Action View
-
Skip blank attribute names in tag helpers to avoid generating invalid HTML.
Mike Dalessio
Action Pack
- No changes.
Active Job
- No changes.
Action Mailer
- No changes.
Action Cable
- No changes.
Active Storage
-
Filter user supplied metadata in DirectUploadController
Jean Boussier
-
Configurable maxmimum streaming chunk size
Makes sure that byte ranges for blobs don't exceed 100mb by default.
Content ranges that are too big can result in denial of service.Gannon McGibbon
-
Limit range requests to a single range
Jean Boussier
-
Prevent path traversal in
DiskService.DiskService#path_fornow raises anInvalidKeyErrorwhen passed keys with dot segments (".",
".."), or if the resolved path is outside the storage root directory.#path_foralso now consistently raisesInvalidKeyErrorif the key is invalid in any way, for
example containing null bytes or having an incompatible encoding. Previously, the exception
raised may have beenArgumentErrororEncoding::CompatibilityError.DiskControllernow explicitly rescuesInvalidKeyErrorwith appropriate HTTP status codes.Mike Dalessio
-
Prevent glob injection in
DiskService#delete_prefixed.Escape glob metacharacters in the resolved path before passing to
Dir.glob.Note that this change breaks any existing code that is relying on
delete_prefixedto expand
glob metacharacters. This change presumes that is unintended behavior (as other storage services
do not respect these metacharacters).Mike Dalessio
Action Mailbox
- No changes.
Action Text
- No changes.
Railties
- No changes.
Guides
- No changes.