# 2.9.0.beta11: Beveiligingsfixes, Nieuwe algemene categorie, Verbeteringen aan de zijbalk en meer

**URL:** https://meta.discourse.org/t/2-9-0-beta11-security-fixes-new-general-category-sidebar-improvements-and-more/243627
**Category:** Announcements
**Tags:** release-notes
**Created:** [1 november 2022 om 17:34 UTC](https://meta.discourse.org/t/2-9-0-beta11-security-fixes-new-general-category-sidebar-improvements-and-more/243627 "2022-11-01T17:34:31Z")
**Posts on this page:** 1
**Showing post:** 1

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [1 november 2022 om 17:34 UTC](https://meta.discourse.org/t/2-9-0-beta11-security-fixes-new-general-category-sidebar-improvements-and-more/243627/1 "2022-11-01T17:34:31Z")

</div>

## New features in 2.9.0.beta11

### Security Updates

This beta includes 3 security fixes for issues reported by our community and [HackerOne](https://hackerone.com/discourse).

- Restrict display of topic titles associated with user badges [CVE-2022-39378](https://github.com/discourse/discourse/security/advisories/GHSA-2gvq-27h6-4h5f)
- Expand and improve SSRF Protections [CVE-2022-39241](https://github.com/discourse/discourse/security/advisories/GHSA-rcc5-28r3-23rr)
- Fix invite link email validation [CVE-2022-39356](https://github.com/discourse/discourse/security/advisories/GHSA-x8w7-rwmr-w278)

#### Plugin Security Updates

Multiple plugins have also received security fixes. Be sure to update plugins in addition to Discourse.

- Patreon: [CVE-2022-39355](https://meta.discourse.org/t/critical-security-fix-for-the-discourse-patreon-plugin/242999)
- Chat: Channel name and description susceptible to XSS [CVE-2022-39279](https://github.com/discourse/discourse-chat/security/advisories/GHSA-qp62-8m3c-9jgj)
- Chat Integration: Insufficient Server Side Request Forgery protections [CVE-2022-39241](https://github.com/discourse/discourse-chat-integration/security/advisories/GHSA-xmc4-3rxg-q8jx)
- OAuth2 Basic: Insufficient Server Side Request Forgery protections [CVE-2022-39241](https://github.com/discourse/discourse-oauth2-basic/security/advisories/GHSA-qj5f-8cm8-rhf8)
- OpenID Connect: Insufficient Server Side Request Forgery protections [CVE-2022-39241](https://github.com/discourse/discourse-openid-connect/security/advisories/GHSA-xp93-7vr3-72c5)

### General is the default category

For sites with the #General category, it will now be automatically selected when a new topic is created.

### New site setting: `require change email confirmation`

We’ve added a new site setting, `require change email confirmation`. When enabled, all users will need to confirm both their current email, and new email when changing it. When disabled, only staff users will need to confirm their current email when changing it.

### Hide welcome topic if it hasn’t been edited

All Discourse sites come with a welcome topic that admins are suggested to edit when setting up their site. This topic is now hidden from non-admin users until an edit is made.

### Sidebar: Allow user to set preferred list destination

Users can choose between `Default` or `new/unread` as the destination when clicking links in the sidebar.

 ![image](https://global.discourse-cdn.com/meta/original/4X/d/a/a/daa4856b53f0802b2db5e45d488ca029e6eff4d8.jpeg)

### Sidebar: Display link for admins when default categories/tags are not configured

We now add a link to the sidebar for admin users when they have not configured the `default_sidebar_categories` or `default_sidebar_tags` site settings

 ![image](https://global.discourse-cdn.com/meta/original/4X/4/0/c/40c618921f7d5e5136dfff484f89e04f9092d6a9.png)

### New user tips (experimental)

> [@New User Tips](https://meta.discourse.org/t/new-user-tips-experimental-feature/243763):
>
> In the latest beta of Discourse, we introduced user tips explaining the most important features of Discourse (enabled by default; to disable it, navigate to your site setting and search for “enable user tips”). At this moment, there are user tips for: first notification topic timeline post menu topic notification level suggested topics admin guide: getting started ([shown to admins on new sites](https://meta.discourse.org/t/updates-to-new-site-experience-and-the-getting-started-guide/273189)) camera_flash Screenshots

### User status configurable via preferences

Custom users statuses can now be configured via account preferences, `/my/preferences/account` in addition to the user menu. This change also allows site setting to edit and/or clear a custom status from a user as needed.

### Dark mode option for category logos

Admins can now upload a second category logo which will be used for dark themes.

---

_[View the full topic](https://meta.discourse.org/t/2-9-0-beta11-security-fixes-new-general-category-sidebar-improvements-and-more/243627)._
