New features in 2.9.0.beta10
Sidebar and new notification menu
Security Updates
This beta includes 4 security fixes for issues reported by our community and HackerOne.
- Handle incomplete quote bbcode (CVE-2022-39232)
- Limit user profile field length (CVE-2022-39226)
- Moderator shouldn’t be able to import a theme via API (CVE-2022-36068)
- Prevent arbitrary file write when decompressing files (CVE-2022-36066)
Remember adjusted composer height
Find the composer’s default height too small? Perhaps you have a smaller screen and think it’s too big? Discourse will now remember when you adjust the composer, and re-open the composer to your selected height each time.
New personal message enabled groups
site setting
The enable personal messages
and min trust to send messages
site settings have been replaced with personal message enabled groups
. Site admins can now configure which groups are able to start personal messages.
Warn when PM’ing a user that hasn’t been on Discourse in a long time
When a user creates a PM and adds a recipient that hasn’t been seen in a long time, a warning is now shown in composer.
Additional features
- Add site setting to disable usernames in share links
- Navigate emoji picker using keyboard arrows
- Add tooltips to timeline start/end dates
- Replace the Lounge category with General on new instances
- Add safe-mode toggle to
/u/admin-login
- Prompt PWA users earlier to enable push notifications
- Adds full screen composer submit button and prompt
Even more!
But wait, there’s more! We do our best to highlight new features and changes for you, but there’s always too many changes to detail. For a full list of new features, bug fixes, UX improvements, and more, be sure to review the Additional Features and Fixes listed below.