Skip to content

Releases: wintercms/winter

v1.2.14

Choose a tag to compare

@LukeTowers LukeTowers released this 19 Aug 22:00

UX/UI Improvements

  • Added previous / next record navigation to backend forms.
  • Added new fieldset FormWidget that visually groups form fields together in the Form widget.

API Changes

  • Public controller methods used as a page action must now be named in lowercase — coming_soon() rather than comingSoon() — and dashed URLs are normalised to snake_case, so /coming-soon now resolves to coming_soon() instead of comingSoon(). Plugins with a camelCase page action should rename the method and its view file to match; the published URL does not need to change

Bug Fixes

  • Improved handling of the password reset flow for users that don't exist.
  • Fixes issue where if an exception is thrown during a Halcyon force deletion it would leave the datastore stuck in force deletion mode.

Security Improvements

  • Improved escaping of BrandSetting & EditorSetting custom CSS settings.
  • Fixed reflected XSS in the backend Table widget.
  • Hardened the image column type to prevent potential XSS from untrusted user input.
  • Tightened import export controller behavior permissions checking.
  • Hardened the MyAccount controller added in v1.2.13.
  • Hardened backend request routing to close off CSRF attacks targeting AJAX handlers.

Translation Improvements

  • Improved Ukrainian translations.

Performance Improvements

  • Reduced front-end database queries from CMS templates, theme data, and request logs.
  • Resolve Halcyon DB template mtimes without a query per check.

Community Improvements

  • Added GitHub action to automatically update the official Winter docker image when new Winter versions are released.

Dependencies

  • Bump minimum version of assetic/framework to v3.2.2.

New Contributors

Full Changelog: v1.2.13...v1.2.14

v1.2.13

Choose a tag to compare

@LukeTowers LukeTowers released this 07 Aug 05:44
e09c8d3

UX/UI Improvements

  • Added support for inline drag-and-drop sorting for lists and relations.
  • Renamed CMS to Theme Editor in the backend menu.
  • Minimized flash of unstyled content when switching between multiple codeeditor instances.
  • Restored AceEditor keyboard shortcuts of (Ctrl|Cmd+Shift+D) for duplicating the current selection & (Ctrl|Cmd+Shift+F) for full screen mode
  • Fixed support for dragging content (i.e. text links, partials, content files) into the CodeEditor field.
  • Fixed highlighting paired tokens in Twig mode by bringing in the full HTML mode processing into Twig mode.
  • Fixed issues caused when swapping between multiple editor instances where editor state (position, selection, folding, history) wasn't being retained across editor disposal.
  • Fixed default "Twilight" theme to more closely match the original Twilight theme used by AceEditor.
  • Improved permission checking to allow users with one of cms.manage_pages, cms.manage_layouts, or cms.manage_partials to still be able to view the list of partials.
  • Improved UX of the Permission Editor formwidget and included better descriptions of riskier permissions.
  • Added basic viewer for event log details.
  • Improved handling of errors when rendering default form controller views.

DX Improvements

  • Added PHP 8.5 to the CI test matrix and improved PHP 8.5 compatibility.
  • Added AGENTS.MD to wintercms/winter to improve the experience of using AI agents to work on the core.

API Changes

  • Added support for the schema:dump command.
  • Enhanced HasSortableRelations for the new inline drag-and-drop sorting provided by the RelationController.
  • Resizer URLs now respond with a 301 redirect instead of a 302 redirect to the resized image.

Bug Fixes

  • Improved handling of terminal signals on Windows.
  • Brought attributesToArray() more in-line with Laravel eliminating several bugs related to using the $casts property in Winter Model classes.
  • Improved validation of Theme directory names.
  • Added support for returning Vite assets in their correct group (i.e. styles vs scripts).
  • Fixed TypeError when removing a non-existent plugin.
  • Fix infinite loop in form widget with circular dependsOn declarations.
  • Improved support for PHP 8.4 & 8.5.
  • Fixed issue where Monaco editor was triggering false dirty state on forms.
  • Fixed issue introduced in 1.2.10 where saving a relation with a User model could trigger authorization checks which could result in a 403 error if the user didn't have permission to update the User model.
  • Improved compatibility with managed hosts that restrict modifying the nginx configuration file by double encoding the dots in resizer URLs.

Security Improvements

  • Fixed issue where environment variables could be leaked through the parsing of INI configuration values (CVE-2026-25125).
  • Improved security of LESS & Javascript imports through the AssetCombiner.
  • Improved escaping of BrandSetting & EditorSetting custom CSS settings.
  • Fixed potential SQL injection with the backend Filter widgets.
  • Fixed potential user account bypasses by moving the My Account page to a dedicated controller.
  • Closed bypasses making use of the legacy AJAX postback handler.
  • Hardened user management by moving more authorization checks directly into the User model itself to prevent modifications at the lowest level.
  • Improved permission checking in the CMS / Theme Editor backend page.
  • Ensured FileUpload formwidget only ever looks at related file records.
  • Hardened Twig Security Policy / Safe Mode logic.
  • Improved user management protection checks by blocking changes to core relationships (avatar, groups, throttle) at the model level.

Translation Improvements

  • Improved Ukranian translations.

Performance Improvements

  • Improved performance of retrieving HasMany relationships.

Community Improvements

Dependencies

  • Upgraded nikic/php-parser to ^5.7

New Contributors

Full Changelog: v1.2.12...v1.2.13

v1.2.12

Choose a tag to compare

@LukeTowers LukeTowers released this 20 Feb 20:58

UX/UI Improvements

  • Added support for tel form field.

Bug Fixes

  • Fixed z-index on MediaManager move dropdown.
  • Fixed support for config properties on URL fields.
  • Fixed issue where dynamically extending a class to add behaviors could fail if the behavior had been added before.

Security Improvements

  • Added protection against privilege escalation attack from authenticated backend users.

Performance Improvements

  • Moved Vite rendering to {% styles %} Twig tag instead of {% scripts %} to prevent FOUC.

Dependencies

  • Improved support for PHP 8.4.

Full Changelog: v1.2.11...v1.2.12

v1.1.12

Choose a tag to compare

@LukeTowers LukeTowers released this 20 Feb 20:57

Security improvements

  • Added protection against privilege escalation attack from authenticated backend users.

Full Changelog: v1.1.11...v1.1.12

v1.0.477

Choose a tag to compare

@LukeTowers LukeTowers released this 20 Feb 20:57

Security improvements

  • Added protection against privilege escalation attack from authenticated backend users.

Full Changelog: v1.0.476...v1.0.477

v1.2.11

Choose a tag to compare

@LukeTowers LukeTowers released this 18 Feb 23:10

UX/UI Improvements

  • Added "Failed Logins" tab to the User account form in the backend to view the throttle records of users and be able to manually unthrottle IPs.
  • Reorganized the fields on the user account page in the backend for ease of use.
  • Added support for autogenerating passwords when creating users in the backend (requires notification email to be sent to the user).
  • Added ability for the CodeEditor to restore its original line location when restoring after being disposed of on a page (i.e. when switching between on-page tabs with multiple codeeditors, like in the CMS Theme Editor).

API Changes

  • Added auto detection of LICENCE and LICENSE files in plugins as their license files.

Bug Fixes

  • Fixed bug introduced in v1.2.10 where collections weren't being supported as a possible value for form field's options property.
  • Fixed bug introduced in v1.2.10 where LESS, SASS, and SCSS files were being treated as PHP files by the CodeEditor in the CMS Theme Editor.
  • Fixed support for type="module" inline script tags when using the Twig language mode with the Monaco CodeEditor.
  • Fixed bug introduced in v1.2.10 where event listeners attached to Theme events from within plugin boot() methods weren't being fired.

Security Improvements

  • Improved automatic sanitization of SVGs through the CMS AssetList widget.

Community Improvements

  • Fix PHP Code block examples for the model.* events in the Winter CMS documentation.

Full Changelog: v1.2.10...v1.2.11

v1.2.10

Choose a tag to compare

@LukeTowers LukeTowers released this 04 Feb 20:42

UX/UI Improvements

  • Replaced the codeeditor's implementation from Ace Editor to Monaco.
  • Improved grouped repeater UX by adding search and multiple columns.
  • Removed the . from the end of the generated password in the output of the winter:passwd command to make it easier to copy.

DX Improvements

  • Fixed support for the Laravel Maintenance mode (artisan down, artisan up) which was broken with the move to Laravel 9 (note: this is separate from the backend / CMS "soft" maintenance mode).
  • Added support for the schedule:list and schedule:work commands from Laravel
  • AutoDatasource caching is now disabled when app.debug is true to avoid issues caused by stale path caches when developing locally.
  • Added llms.txt and .user.ini to the list of mirrored files.
  • Made the dropdown field use the Form::select() helper internally for consistency.
  • Made the repeater's titleFrom property less picky about what type of field it can pull the value from.

API Changes

  • Add support for images / icons in options with the Form::select() helper.

Bug Fixes

  • Fixed issue where emptyOption wasn't being removed in the Form::select() helper after being used to populate the placeholder.
  • Fixed issue where the FontAwesome assets downloaded by the winter:util compile less command weren't being pinned to a specific version.
  • Fixed issue where fancy layout form styles were bleeding into modals.
  • Fixed issue where the loading indicator wouldn't hide after receiving a RedirectResponse for file downloads through the AJAX framework.

Security Improvements

  • Sanitize SVG files when uploaded to the theme assets.
  • Improved escaping of EditorSettings, BrandSettings, & MailBrandSettings.

Translation Improvements

  • Improved Ukrainian translation.

Community Improvements

New Contributors

Full Changelog: v1.2.9...v1.2.10

v1.2.9

Choose a tag to compare

@LukeTowers LukeTowers released this 15 Oct 20:52

UX/UI Improvements

  • Added support for setting failover transports to the backend Mail Settings page.

DX Improvements

  • config:clear command now warns users that caching configuration files is not currently supported in Winter CMS.
  • Improved create:command scaffolder to allow for hyphens in generated command names and added optional --description option to set the help text for the generated command.
  • Enhanced winter:util compile to download FontAwesome assets required to compile backend LESS files if not present.
  • Added the Form's id attribute to the forms generated by the default FormController views.
  • Registered the Illuminate\Contracts\Auth\Access\Gate contract with the application as a null gate to prevent plugins and IDE extensions that expect the contract to be present from throwing unhelpful errors.
  • Exceptions passed to the Backend\Traits\ErrorMaker trait are now logged in the backend error log (excluding ApplicationExceptions).

API Changes

  • Added iconClass option for the fileupload FormWidget to specify the icon that should be used for the upload button.
  • Added search widget configuration options to the RelationController's view & manage mode configuration (prompt, mode, scope, searchOnEnter).

Bug Fixes

  • Improved compatiblity of Winter's ConfigRepository with Laravel by aliasing top level config keys (currently prefixed with *:: to reflect the namespaced config system used in Winter) to their naked versions (i.e. debugbar is still internally stored as *::debugbar but will also be accessible from the getItems() and all() methods on the ConfigRepository as debugbar). This paves the way for support for Laravel Nightwatch which relies on directly accessing the underlying config data structure for performance reasons.
  • Improved handling of package names as input to the vite:compile and vite:watch commands.
  • Fixed issue where winter:util purge uploads could sometimes delete files that were actually in use.
  • Improved vite base path generation to fix importing fonts.
  • Improved error handling when using the default FormController views.
  • Improved handling of form data in Snowboard.request() to skip null or undefined values.
  • Removed the registration of the non-existant Backend\FormWidgets\TimePicker FormWidget.
  • Updated bootstrap/autoload.php to return a 500 header when the vendor files are not present.
  • Fixed issue with the DataTable widget not being able to actually save data.
  • Fixed Preview labeling on the fancy toolbar for the default FormController view.

Security Improvements

  • Ignored vendor & node_modules in the default .gitignore to ensure that those directories are ignored at every level of the project, not just at the project root.

Community Improvements

Dependencies

  • Improved support for PHP 8.4.

New Contributors

Full Changelog: v1.2.8...v1.2.9

v1.2.8

Choose a tag to compare

@LukeTowers LukeTowers released this 25 Jun 22:47

UX/UI Improvements

  • Added a beautiful error log viewer in the backend that displays contextual information about exceptions, links directly to the source files, and unrolling of all previous exceptions in the stack.
  • Added new button field type to make it easier to add custom buttons to backend forms.
  • Added support for the url field type to the backend forms.
  • Added email icon to email fields.
  • Updated the default backend branding colours to match the Winter CMS Brand Guidelines.
  • Added support for shift clicking to select multiple records at once in the Lists widget.
  • Removed the sort icon from columns that aren't sortable and display a right arrow when a column is sortable but isn't currently being used to sort the results.
  • Added button-group and dropdown filter scope types.
  • Made the entire mediafinder field clickable when mode: file.
  • Improve click behaviour of recordfinder fields when disabled.
  • Allow users to zoom the backend on mobile.
  • Added support for abort(403) to return the access denied view in the backend
  • Improved handling of abort(404) in the backend
  • Improved styling of disabled fields in the fancy form layout
  • Hide the select all checkbox on the Lists widget when there are no records to select.
  • Fixed anchor tag outline styling in Firefox.
  • Style read-only columns on Table widget with slightly darker grey background to indicate read-only state.
  • Allow tab and arrow navigation for read-only columns on the Table widget.
  • Allowed searching option to show search box on the Table widget even if adding and deleting buttons are disabled.
  • Fixed styling of toolbar on the Table widget if only the search box is shown (no background previously).
  • Fixed styling of pagination on Table widget.
  • Default to ignoreTimezone = true for date columns.

DX Improvements

  • Added default views for the following backend controller behaviors (FormController, ImportExportController, ListController, ReorderController)
  • Backend controllers will now automatically set their navigation context in the form of Author.Plugin as the author, $pluginName as the main menu code, and $controllerName as the side menu code. This means that you can remove calls to BackendMenu::setContext() and constructor overrides in your controllers if they follow that convention.
  • Improved styling of file generated / updated status message in scaffolding commands
  • Added support for ReactJS in Vite & Mix compiled asset packages.
  • Added support for customizing the Vite build directory.
  • Improved support for Model Factories.
  • Added test alias for the winter:test command.
  • Added schedule_timezone property to config/app.php.
  • Updated theme scaffold's README.md to reflect the use of Vite in the generated themes.
  • Added Mail::sendTo() method to the Mail facade's docblock.
  • Added support for modules to the asset:create commands (mix:create, vite:create).
  • Make readOnly option case-insensitive on the Table widget.
  • Improvements to the default scaffolding stub files to bring more inline with the future PSR-12 coding style update.

API Changes

  • Added typehints to all the method signatures on the base Winter\Storm\Database\Attach\File model. (eg. getPath(), getCacheKey(), getFilename(), getContents(), getDiskPath(), isPublic(), etc).
  • Added metadata jsonable column to the base File model, migrations have been added for system_files, but if you use a custom files table you will need to add a migration that adds $table->mediumText('metadata')->nullable(); to your files table.
  • Made getDiskName() on the base Winter\Storm\Database\Attach\File model public.
  • Added support for an array of names to use for the postbackHandlerName in the Table widget.
  • Removed the config:cache command as it wasn't improving our performance and didn't fully work with Winter's flexible configuration system.
  • Added support for SystemException and ApplicationException instances to define their own response codes.
  • Added appendViewPath() and prependViewPath() to the System\Traits\ViewMaker. addViewPath is renamed to prependViewPath() and is for paths that have higher priority than the existing paths while appendViewPath() is for paths that should have lower priority than the existing paths (i.e. fallbacks).
  • Behaviors extending Backend\Classes\ControllerBehavior will now automatically append their views folder to the controller's view paths allowing them to provide fallbacks for any views required by the behavior.
  • The create:controller command will now no longer generate the views by default unless --stubs is also passed and the --sidebar flag is replaced with a --layout=(standard|sidebar|fancy) option to choose the form layout to use.
  • Support for passing new: true as a parameter in the request body to onSave() calls that will return a redirect to the create action
  • formMakePartial(string $partial, array $params = []) to the FormController behavior that will render a partial through the controller's makePartial using the following priority list of contextual names (form_$context_$partial, form_$partial, $partial).
  • Added PromptsForMissingInput to the base Winter\Storm\Console\Command class.
  • Removed the unused (and broken) Winter\Storm\Database\DataFeed class.
  • PluginTestCase now resets the application router in the setUp() method between test runs to ensure that plugin routes load in the correct order during tests.

Bug Fixes

  • Removed redundant backend route.
  • Fixed issues where TagList & Repeater FormWidgets were not able to save an empty value.
  • Fixed issue where TagList could return an object in array mode.
  • Fixed using Vite packages when they are explicitly ignored / excluded from the project's package.json.
  • Improved support for winter:mirror on Windows
  • Using the {% flash %} tag in Twig will now properly purge the FlashBag after it has been read.
  • Improved support for plugins attempting to access the database before it's fully ready to go.
  • Fixed suport for hex colors with alpha values.
  • Fixed infinite loop that occurrs when the configured database exists but the tables don't exist yet.
  • Fixed support for array callables as dynamic methods.
  • Event listeners bound to events with bindEventOnce() now properly unbind after execution, even if the event is a halting event.
  • Fixed Syntax Error in CAST Statement for Postgres attachment.
  • Fixed CMS Maintenance Mode not working when the allowed_ips setting has a value but a null list of IPs.
  • Fixed CMS Maintenance Mode settings page not showing the correct value for when the Maintenance Mode is enabled.
  • Improved support for using hasManyThrough / hasOneThrough relationships with soft deletes.
  • Fixed support for the --force flag in winter:env.
  • Improved support for defining multiple Vite entrypoints.
  • Prevent crashes when rendering invalid values in datepicker fields.
  • Prevent editors from being created for all column types in the Table widget if read-only (previously, only string columns would be rendered read-only by setting the readonly attribute, this is not ideal because it can be easily changed).
  • Fixed broken search if client datasource is used on the Table widget.
  • Fixed addVite() method not being able to bind assets to the parent controller.
  • Fixed displaying the status of maintenance mode triggered through the backend.
  • Fixed backend-triggered maintenance mode support for defined but empty IP lists.
  • Fixed support for hex colors with alpha values in the colorpicker FormWidget.
  • Improved handling of registering / booting plugins when migrations haven't been run yet.

Security Improvements

  • Added AllowList functionality to the Twig security policy.

Translation Improvements

  • Improved Russian translations.
  • Improved Dutch translations.

Performance Improvements

  • Switched to a number input instead of a select dropdown for direct navigation to list pages in the Lists widget. Drastically improves performance when a list has 100+ pages in the results as it no longer causes an N+1 performance issue of rendering a single option element for every single page in your results.
  • Fixed an infinite loop that could occur when a database was present but plugin migrations hadn't been run yet.

Community Improvements

  • Added Laravel to the list of organizational sponsors.
  • Removed Route4Me from the list of organizational sponsors.

Dependencies

  • Added support for PHP 8.4
  • Dropped support for PHP 8.0, PHP 8.1 is now the minimum requirement.
  • wikimedia/less has been bumped to v5 from v3.
  • Minimum Laravel version has been bumped to v9.49.

New Contributors

Full Changelog: v1.2.7...v1.2.8

v1.1.11

Choose a tag to compare

@bennothommo bennothommo released this 09 Dec 06:34

Security improvements

  • Improved the Twig security policy (blocked methods that write, delete, or modify records and attributes in Database/Eloquent and Halcyon models; blocked access to the theme datasource; prevented extensions from being created or directly interacted with). See GHSA-xhw3-4j3m-hq53 for more information.

Full Changelog: v1.1.10...v1.1.11