1.9.7
Appwrite 1.9.7 is a security patch for the 1.9 line. It closes two migration paths that could read data a user should not reach, expires JWTs together with their session, and hardens the builds worker. It ships with the 8.7.37 self-hosted Console (was 8.7.30). Upgrading from 1.9.6 needs no migration changes. If you are on 2.x, this release does not apply to you.
Highlights
- Migration sources must be public. Appwrite → Appwrite migrations now reject source endpoints that are not public http(s) addresses, and pin every source request to the addresses that were validated, so a migration cannot be pointed at internal services. To migrate from a source on a private network, list it in the new
_APP_MIGRATIONS_ALLOWED_HOSTS. (#14036) - Source keys are checked before a local migration. A migration whose endpoint is this instance now authenticates the submitted API key against the source project before reading its database. Before, a project admin could copy another project's databases on the same instance. (#14005)
- Console 8.7.37, which fixes the row editor rendering every array column as a string input. (#13130)
Fixes
Auth
- Reject a JWT once the session it was created from has expired. Before, a JWT stayed valid for its own duration after its session expired. (#13169, Fixes #8000)
Functions and Sites
- Quote the build directory passed to
tar, so root directories with spaces or quotes build correctly. (#14006)
Avatars
- Remove the unused, undocumented
/v1/cards/cloud*endpoints. (#14067)
Under the hood
utopia-php/migration1.14.2 andutopia-php/mongo1.5.4 (replacingmongodb/mongodb)- Browser service 0.3.4
- The release workflow no longer moves the
latestimage tag, so publishing a 1.9.x patch leaveslateston 2.x
Install
docker run -it --rm \
--volume /var/run/docker.sock:/var/run/docker.sock \
--volume "$(pwd)"/appwrite:/usr/src/code/appwrite:rw \
--entrypoint="install" \
appwrite/appwrite:1.9.7
Upgrade
Run the same command with --entrypoint="upgrade", then migrate:
cd appwrite
docker compose exec appwrite migrate
The migration stays on V25 and has nothing new to run if you are on 1.9.6. The new compose file passes _APP_MIGRATIONS_ALLOWED_HOSTS to appwrite and appwrite-worker-migrations, and bumps appwrite-console to 8.7.37 and appwrite-browser to 0.3.4.
Before upgrading, check this:
- Migrations from private hosts: if you migrate from an Appwrite instance on a private address or hostname (for example another instance on your LAN), set
_APP_MIGRATIONS_ALLOWED_HOSTSto a comma-separated list of its hostnames, IPs or CIDR ranges. It is empty by default, which allows public sources only. (#14036)
Back up your data first.
Contributors
Thank you to everyone who contributed to 1.9.7:
@abnegate @HarshMN2345 @loks0n @ChiragAgg5k