Ozzy47
Administrator
- Thread starter Thread starter XenForo
- Start date Start date Today at 1:42 PM
In addition to the usual bug fixes, XenForo 2.3.5 includes a critical security fix for any customers making use of OAuth2 where client applications may be able to request unauthorized scopes. This will affect any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5.
Directly from your admin control panel
If you are a XenForo Cloud customer, your upgrade will be scheduled automatically.
Some of the changes in XF 2.3.5 include:
- Fix unassociated attachment limit checks
- Clamp client-side color contrast evaluations
- Appropriately load tweets after page load.
- Update Twitter connected account references to X.
- Fix X (formerly Twitter) connected account
- Ensure xf_oauth_client and xf_oauth_request have primary keys.
- Allow a Passkey credential_id to occupy up to 1024 characters.
- Make code editor search highlighting similar to editor selection color.
- Remove unused jQuery snippet.
- Fix reactions tabs for direct message replies.
- Support multiple variation menus when updating variations
- Fix number box handling when step value is
any
- Fix a server error when no custom error phrase is specified for an error response
- Improve type hinting of schema manager closures
- Properly reset write-pending status when calling
Entity::saveIfChanged
- Fix server error when log search results return a record for a deleted user
- Properly represent field and prefix user group IDs as a list of unique sorted integers
- Support lazy-loading variation pictures
- Suppress PhpStorm warnings in class extension hint files
- Fix unstable sort order for class extension output
- Fix potentially undefined array key when determining an entity cover image
- Properly validate OAuth client redirect URIs
- Pass import command interactive state to import-finalize command
- Improve BBCode HTML rendering PHP 8.3 compatibility
- Do not escape HTML when rendering custom field titles in the control panel
- Allow saving cookie preferences when board is inactive
- Fix duplicate moderated icon in article preview thread titles
- Allow fetching all server globals using
\XF\Http\Request::getServerInfo
- Fix incorrect phrase in user change log handler
- Fix handling of
null
auto-complete results - Do not scroll to last viewed image when closing the lightbox
- Fix error 'TemplateFinder::searchTitle() accepts 1 parameters but 2 are passed'
- Fix server error getting conversations by ID via API.
- Fix incorrect route format for the OAuth2 account/applications route
- Fix issue where code challenges for public OAuth2 clients could not be verified
The following public templates have had changes:
- code_editor.less
- connected_account_associated_x
- connected_account_macros
- core_button.less
- editor_insert_gif
- helper_js_global
- login
- passkeys_macros
- post_article_macros
- share_page_macros
- style_variation_macros
As always, new releases of XenForo are free to download for all customers with active licenses. You may now upgrade from your admin control panel or grab the new version from the customer area.
Please note that XenForo 2.3 has higher system requirements than earlier versions.
The following are minimum requirements:
- PHP 7.2 or newer (PHP 8.3 recommended)
- MySQL 5.7 and newer (Also compatible with MariaDB/Percona etc.)
- All of the official add-ons require XenForo 2.3.
- Enhanced Search requires at least Elasticsearch 7.2.
Installation and upgrade instructions
Full details of how to install and upgrade XenForo can be found in the XenForo 2 Manual. We strongly recommend upgrading directly from within your control panel.Written by
Company info
There is no better platform upon which to grow your community.
Engage your customers with the premium community experience.
Staff member
- Messages
698 - Reaction score
24,690 - Points
503
XenForo Media Gallery 2.3.5 Released
XenForo Media Gallery 2.3.5 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo Media Gallery 2.3 upgrade to this release to benefit from increased stability.Directly from your admin control panel
If you are a XenForo Cloud customer, your upgrade will be scheduled automatically.
The following public templates have had changes:
- xfmg_media_add_macros
XenForo Media Gallery requires XenForo 2.3 or later.
XenForo Media Gallery can be purchased with a new license via the purchase page or with an existing license via the customer area.
Installation, upgrading and configuration
Please see our XenForo Media Gallery manual page for more information.
XenForo Resource Manager 2.3.5 Released
XenForo Resource Manager 2.3.5 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo Resource Manager 2.3 upgrade to this release to benefit from increased stability.Directly from your admin control panel
If you are a XenForo Cloud customer, your upgrade will be scheduled automatically.
XenForo Resource Manager requires XenForo 2.3 or later.
XenForo Resource Manager can be purchased with a new license via the purchase page or with an existing license via the customer area.
Installation, upgrading and configuration
Please see our XenForo Resource Manager manual page for more information.
XenForo Enhanced Search 2.3.5 Released
XenForo Enhanced Search 2.3.5 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo Enhanced Search 2.3 upgrade to this release to benefit from increased stability.Directly from your admin control panel
If you are a XenForo Cloud customer, your upgrade will be scheduled automatically.
Some of the changes in XFES 2.3.5 include:
XenForo Enhanced Search requires XenForo 2.3 or later.
XenForo Enhanced Search can be purchased with a new license via the purchase page or with an existing license via the customer area.
Installation, upgrading and configuration
Please see our XenForo Enhanced Search manual page for more information.
Continue reading...