Catalog / Appwrite

1.9.7

3 days agosecurityaddedfixedOriginal notes

Appwrite 1.9.7 is a security patch for the 1.9 line. It closes two migration paths that could read data a user should not reach, expires JWTs together with their session, and hardens the builds worker. It ships with the 8.7.37 self-hosted Console (was 8.7.30). Upgrading from 1.9.6 needs no migration changes. If you are on 2.x, this release does not apply to you.

Highlights

  • Migration sources must be public. Appwrite → Appwrite migrations now reject source endpoints that are not public http(s) addresses, and pin every source request to the addresses that were validated, so a migration cannot be pointed at internal services. To migrate from a source on a private network, list it in the new _APP_MIGRATIONS_ALLOWED_HOSTS. (#14036)
  • Source keys are checked before a local migration. A migration whose endpoint is this instance now authenticates the submitted API key against the source project before reading its database. Before, a project admin could copy another project's databases on the same instance. (#14005)
  • Console 8.7.37, which fixes the row editor rendering every array column as a string input. (#13130)

Fixes

Auth

  • Reject a JWT once the session it was created from has expired. Before, a JWT stayed valid for its own duration after its session expired. (#13169, Fixes #8000)

Functions and Sites

  • Quote the build directory passed to tar, so root directories with spaces or quotes build correctly. (#14006)

Avatars

  • Remove the unused, undocumented /v1/cards/cloud* endpoints. (#14067)

Under the hood

  • utopia-php/migration 1.14.2 and utopia-php/mongo 1.5.4 (replacing mongodb/mongodb)
  • Browser service 0.3.4
  • The release workflow no longer moves the latest image tag, so publishing a 1.9.x patch leaves latest on 2.x

Install

docker run -it --rm \
    --volume /var/run/docker.sock:/var/run/docker.sock \
    --volume "$(pwd)"/appwrite:/usr/src/code/appwrite:rw \
    --entrypoint="install" \
    appwrite/appwrite:1.9.7

Upgrade

Run the same command with --entrypoint="upgrade", then migrate:

cd appwrite
docker compose exec appwrite migrate

The migration stays on V25 and has nothing new to run if you are on 1.9.6. The new compose file passes _APP_MIGRATIONS_ALLOWED_HOSTS to appwrite and appwrite-worker-migrations, and bumps appwrite-console to 8.7.37 and appwrite-browser to 0.3.4.

Before upgrading, check this:

  • Migrations from private hosts: if you migrate from an Appwrite instance on a private address or hostname (for example another instance on your LAN), set _APP_MIGRATIONS_ALLOWED_HOSTS to a comma-separated list of its hostnames, IPs or CIDR ranges. It is empty by default, which allows public sources only. (#14036)

Back up your data first.

Contributors

Thank you to everyone who contributed to 1.9.7:

@abnegate @HarshMN2345 @loks0n @ChiragAgg5k