# 3.4.0.beta4：重新设计的表情符号、导出用户数据、举报非法内容等

**URL:** https://meta.discourse.org/t/3-4-0-beta4-redesigned-emojis-exporting-user-data-flagging-illegal-content-and-more/349299
**Category:** Announcements
**Tags:** release-notes
**Created:** [2025年二月5日 14:26 UTC](https://meta.discourse.org/t/3-4-0-beta4-redesigned-emojis-exporting-user-data-flagging-illegal-content-and-more/349299 "2025-02-05T14:26:56Z")
**Posts on this page:** 1
**Showing post:** 1

<div class="post-metadata">

### Author: ![Saif](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/saif/32/318253_2.png) [@Saif](https://meta.discourse.org/u/Saif)
#### Post date: [2025年二月5日 14:26 UTC](https://meta.discourse.org/t/3-4-0-beta4-redesigned-emojis-exporting-user-data-flagging-illegal-content-and-more/349299/1 "2025-02-05T14:26:56Z")

</div>

## 3.4.0.beta4 中的新功能

### 重新设计的表情符号

表情符号选择器现在在撰写器中使用 🙂 图标。输入表情符号时，选择一个表情符号将替换任何部分输入的文本。此外，表情符号菜单的定位、大小和通用行为也得到了一些修复。

### 导出用户数据

管理员现在可以通过用户导出部分导出单个用户数据，该部分在管理员设置中选择特定用户时可用，这在需要提供数据以符合合规性要求的情况下可能很有用。

 ![This image shows a user export option with a file named "user_archive.lauri-2502-05-2023-143713-1.zip" available for download, which is 85.4 KB in size and is set to expire in 35 hours. (Captioned by AI)](https://global.discourse-cdn.com/meta/original/4X/f/e/6/fe68c0c1a721d7cbd1c7b329b3519e63ecb08399.png)

### 标记非法内容

信任级别 0 (TL0) 和匿名用户现在可以标记和举报非法内容。

### 一致的管理员设置

管理员设置现在仅在您单击侧边栏中的任何包含设置的项目（例如，垃圾邮件、实验性、速率限制等）时，在专用页面上显示相关的站点设置。

## 安全更新

此版本包括对我们社区和 [HackerOne](https://hackerone.com/discourse) 报告的以下安全问题的修复。

- 通过主题标题进行 XSS（当 CSP 禁用时）([CVE-2024-53266](https://github.com/discourse/discourse/security/advisories/GHSA-hw4j-4hg7-22h2))
- 通过内联 onebox 进行部分 DoS ([CVE-2024-53851](https://github.com/discourse/discourse/security/advisories/GHSA-49rv-574x-wgpc))
- 可能绕过聊天权限 ([CVE-2024-53994](https://github.com/discourse/discourse/security/advisories/GHSA-mrpw-gwj7-98r6))
- 用户可以看到其他用户的标记的 PM ([CVE-2024-56197](https://github.com/discourse/discourse/security/advisories/GHSA-xmgr-g9cp-v239))
- 通过 Onebox URL 进行 HTMLi (XSS，无 CSP) ([CVE-2024-56328](https://github.com/discourse/discourse/security/advisories/GHSA-j855-mhxj-x6vg))
- 存储的基于 DOM 的 XSS（无 CSP）（通过视频占位符）([CVE-2025-22602](https://github.com/discourse/discourse/security/advisories/GHSA-jcjx-694p-c5m3))
- 使用激活帐户路由进行客户端路径遍历 ([CVE-2025-22601](https://github.com/discourse/discourse/security/advisories/GHSA-gvpp-v7mp-wxxw))
- 通过 XHR 请求进行匿名缓存中毒 ([CVE-2024-55948](https://github.com/discourse/discourse/security/advisories/GHSA-2352-252q-qc82))
- 通过请求标头进行匿名缓存中毒 ([CVE-2025-23023](https://github.com/discourse/discourse/security/advisories/GHSA-5h4h-2f46-r3c7))

---

_[View the full topic](https://meta.discourse.org/t/3-4-0-beta4-redesigned-emojis-exporting-user-data-flagging-illegal-content-and-more/349299)._
