Commit Graph
100 Commits
Author SHA1 Message Date
Manuel e9c85dfe40 fix: LiveQuery discloses object data to a subscriber across an ACL read-access change ([GHSA-97pr-9hgg-3p8r](https://github.com/parse-community/parse-server/security/advisories/GHSA-97pr-9hgg-3p8r)) (#10515) 2026-06-19 02:13:55 +02:00
Manuel 1103c7a890 fix: Denial of service via exponential-time processing of deeply nested query operators ([GHSA-cgxm-vr2f-6fj8](https://github.com/parse-community/parse-server/security/advisories/GHSA-cgxm-vr2f-6fj8)) (#10511) 2026-06-17 16:21:23 +02:00
Manuel be12a60d65 fix: Stored XSS via non-standard file extension bypassing file upload extension blocklist ([GHSA-v8x7-r927-cc93](https://github.com/parse-community/parse-server/security/advisories/GHSA-v8x7-r927-cc93)) (#10505) 2026-06-16 02:42:38 +02:00
Manuel 30f1612a2d test: LiveQuery cross-origin connections receive only public-read data (#10504) 2026-06-13 23:16:40 +02:00
Manuel f8612109e3 fix: Middleware route checks do not match routing-equivalent path variants (trailing slash, case) (#10501) 2026-06-12 13:03:10 +02:00
Manuel 880e8e6929 fix: rateLimit on exact static routes is bypassed by appending a query string (#10500) 2026-06-11 03:11:49 +02:00
Manuel 3fad4fb1c4 fix: LiveQuery subscriptions leak when a client reuses a subscribe requestId (#10499) 2026-06-11 01:48:30 +02:00
Manuel f12e1c3e31 fix: Cloud Function multipart requests bypass the maxUploadSize limit (#10498) 2026-06-06 02:43:56 +02:00
Manuel 78859a9bc7 docs: Clarify that rateLimit applies to REST API routes only and not to GraphQL operations (#10496) 2026-06-05 00:40:33 +02:00
Manuel 43658f1fd8 fix: Relation $relatedTo query bypasses protectedFields and owning-object ACL ([GHSA-wmwx-jr2p-4j4r](https://github.com/parse-community/parse-server/security/advisories/GHSA-wmwx-jr2p-4j4r)) (#10493) 2026-06-04 01:52:43 +02:00
Manuel 83e90edbe4 fix: Endpoints /login and /verifyPassword disclose MFA secrets and protected fields when _User get is denied ([GHSA-75v4-m273-5j49](https://github.com/parse-community/parse-server/security/advisories/GHSA-75v4-m273-5j49)) (#10492) 2026-06-03 16:41:16 +02:00
Manuel 66484ce8fd fix: Stored XSS via trailing-dot filename bypassing file upload extension blocklist ([GHSA-7wqv-xjf3-x35v](https://github.com/parse-community/parse-server/security/advisories/GHSA-7wqv-xjf3-x35v)) (#10489) 2026-06-01 23:36:26 +02:00
Manuel 552c6dd754 fix: Server option routeAllowList is bypassable through batch sub-requests ([GHSA-p84r-h6rx-f2xr](https://github.com/parse-community/parse-server/security/advisories/GHSA-p84r-h6rx-f2xr)) (#10482) 2026-05-27 22:41:48 +02:00
Manuel 0ae0ed382b test: GraphQL endpoint is exempt from routeAllowList by design (#10480) 2026-05-27 00:36:20 +02:00
Manuel 155123ade9 fix: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers ([GHSA-8cph-rgr4-g5vj](https://github.com/parse-community/parse-server/security/advisories/GHSA-8cph-rgr4-g5vj)) (#10467) 2026-05-18 17:04:56 +02:00
Manuel 56c159ec96 fix: Pre-authentication denial of service via client version header regex backtracking ([GHSA-38m6-82c8-4xfm](https://github.com/parse-community/parse-server/security/advisories/GHSA-38m6-82c8-4xfm)) (#10463) 2026-05-17 15:11:10 +01:00
Manuel eb6441362a build: Release (#10452) 2026-05-01 13:14:53 +01:00
Manuel 9fee1a0708 feat: Add installation deviceToken deduplication options (#10451) 2026-04-30 23:11:39 +01:00
Manuel 725be0d602 fix: MFA SMS one-time password accepted twice under concurrent login ([GHSA-jpq4-7fmq-q5fj](https://github.com/parse-community/parse-server/security/advisories/GHSA-jpq4-7fmq-q5fj)) (#10448) 2026-04-26 03:10:27 +01:00
Manuel f26700e39d feat: Add rawValues and rawFieldNames options for aggregation queries (#10438) 2026-04-17 09:12:18 +01:00
Manuel fc53270dbe test: Fix socket hang up in node-fetch 3.3.2 fails tests (#10443) 2026-04-17 01:39:53 +01:00
Manuel f303f752c6 refactor: Bump node-fetch from 3.2.10 to 3.3.2 (#10441) 2026-04-17 01:52:11 +02:00
Manuel 163d7be605 refactor: Bump jsonwebtoken from 9.0.2 to 9.0.3 (#10440) 2026-04-17 01:19:05 +02:00
Manuel cbd1da7be3 refactor: Bump path-to-regexp from 8.4.0 to 8.4.2 (#10439) 2026-04-16 13:39:55 +02:00
Manuel b3dedd0482 build: Release (#10430) 2026-04-12 11:25:40 +01:00
Manuel fd31159859 fix: Facebook Standard Login missing app ID validation (#10429) 2026-04-12 01:16:11 +01:00
Manuel 39af946200 refactor: Bump @babel/cli from 7.27.0 to 7.28.6 (#10424) 2026-04-10 21:45:42 +01:00
Manuel 8b80e55afd refactor: Bump otpauth from 9.4.0 to 9.5.0 (#10423) 2026-04-10 21:22:07 +01:00
Manuel b55880d702 refactor: Bump typescript-eslint from 8.53.1 to 8.58.0 (#10422) 2026-04-10 20:51:40 +01:00
Manuel bf40004d25 feat: Add requestComplexity.subqueryLimit option to limit subquery results (#10420) 2026-04-10 16:49:34 +01:00
Manuel 18482e386c feat: Add requestComplexity.allowRegex option to disable $regex query operator (#10418) 2026-04-09 18:12:12 +01:00
Manuel d7d5ae56f7 test: Fix flaky LiveQuery tests caused by session token leak (#10415) 2026-04-08 00:36:45 +01:00
Manuel 7d4a4607fa test: LiveQuery disconnect does not clear subscription info (#10414) 2026-04-08 00:11:55 +01:00
Manuel c0889c8575 fix: Master key does not bypass protectedFields on various endpoints (#10412) 2026-04-07 13:48:39 +01:00
Manuel 8a3db3b966 fix: Endpoints /login and /verifyPassword ignore _User protectedFields (#10409) 2026-04-07 13:01:11 +01:00
Manuel c136e2b7ab fix: Endpoint /upgradeToRevocableSession ignores _Session protectedFields (#10408) 2026-04-07 10:09:09 +01:00
Manuel d5075758f6 fix: Endpoint /sessions/me bypasses _Session protectedFields ([GHSA-g4v2-qx3q-4p64](https://github.com/parse-community/parse-server/security/advisories/GHSA-g4v2-qx3q-4p64)) (#10406) 2026-04-06 17:46:32 +01:00
Manuel 9168e69cb7 test: Webhook overwrites Cloud Code function warning (#10400) 2026-04-05 22:08:12 +01:00
Manuel 531b9ab6dd fix: Login timing side-channel reveals user existence ([GHSA-mmpq-5hcv-hf2v](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmpq-5hcv-hf2v)) (#10398) 2026-04-05 17:48:57 +01:00
Manuel f7f354226e ci: Replace third-party GitHub Actions with trusted alternatives (#10397) 2026-04-04 20:00:25 +01:00
Manuel a3f36a2ddb feat: Add support for invoking Cloud Function with multipart/form-data protocol (#10395) 2026-04-04 17:46:51 +01:00
Manuel fc117efa4d feat: Add server option fileDownload to restrict file download (#10394) 2026-04-03 19:41:42 +01:00
Manuel 19716ad9af fix: Bump lodash from 4.17.23 to 4.18.1 (#10393) 2026-04-03 19:01:02 +01:00
Manuel a4bf3fe145 refactor: Bump semver from 7.7.2 to 7.7.4 (#10392) 2026-04-03 18:14:19 +01:00
Manuel 7d8b367e0b fix: Maintenance key IP mismatch silently downgrades to regular auth instead of rejecting (#10391) 2026-04-03 17:36:27 +01:00
Manuel f2d06e7b95 feat: Add route block with new server option routeAllowList (#10389) 2026-04-03 16:08:18 +01:00
Manuel dd7cc41a95 fix: File upload Content-Type override via extension mismatch ([GHSA-vr5f-2r24-w5hc](https://github.com/parse-community/parse-server/security/advisories/GHSA-vr5f-2r24-w5hc)) (#10383) 2026-04-02 02:19:26 +01:00
Manuel ead12bd1df fix: Session field guard bypass via falsy values for ACL and user fields (#10382) 2026-04-01 21:25:30 +01:00
Manuel b587767aa3 test: Plaintext password accessible in beforeSave trigger on _User class (#10380) 2026-04-01 20:40:18 +01:00
Manuel df5cd46c83 refactor: Bump @parse/push-adapter from 8.3.1 to 8.4.0 (#10381) 2026-04-01 20:32:33 +01:00
Manuel c7814b4429 refactor: Bump jsdoc from 4.0.4 to 4.0.5 (#10379) 2026-04-01 19:35:38 +01:00
Manuel 03be0c07e9 docs: Add multi-tenancy section to README (#10378) 2026-04-01 18:05:08 +01:00
Manuel b4888948b5 refactor: Bump @graphql-tools/utils from 10.8.6 to 11.0.0 (#10377) 2026-04-01 17:55:25 +01:00
Manuel 225a4bb2ad test: CLI execution tests fail on Node 22 due to late stderr callback (#10376) 2026-04-01 16:46:24 +01:00
Manuel 66350964c8 fix: Nested batch sub-requests cause unclear error (#10371) 2026-04-01 14:35:25 +01:00
Manuel 82edbd747c refactor: Bump uuid from 11.1.0 to 13.0.0 (#10370) 2026-03-31 17:57:06 +01:00
Manuel 1cea69a6fa refactor: Bump yaml from 2.8.2 to 2.8.3 (#10369) 2026-03-31 15:55:48 +01:00
Manuel eae967cd53 refactor: Bump lint-staged from 16.2.7 to 16.4.0 (#10368) 2026-03-31 13:53:50 +01:00
Manuel 8a581e940f refactor: Upgrade ws to 7.5.10 (GHSA-3h5v-q93c-6h6q) (#10363) 2026-03-31 02:41:17 +01:00
Manuel a0b0c69fc4 fix: Streaming file download bypasses afterFind file trigger authorization ([GHSA-hpm8-9qx6-jvwv](https://github.com/parse-community/parse-server/security/advisories/GHSA-hpm8-9qx6-jvwv)) (#10361) 2026-03-31 00:17:57 +01:00
Manuel 54c835e0fa refactor: Bump mime from 4.0.7 to 4.1.0 (#10360) 2026-03-30 20:38:12 +01:00
Manuel 2f7dd2e4bb refactor: Bump express-rate-limit from 8.3.0 to 8.3.1 (#10359) 2026-03-30 19:32:34 +01:00
Manuel 2f2c548605 refactor: Bump @babel/preset-env from 7.27.2 to 7.29.2 (#10358) 2026-03-30 18:13:15 +01:00
Manuel 6d0bd1eb40 build: Release (#10354) 2026-03-30 01:30:17 +01:00
Manuel aea7596cd2 feat: Extend storage adapter interface to optionally return matchedCount and modifiedCount from DatabaseController.update with many: true (#10353) 2026-03-30 01:09:10 +01:00
Manuel d5f5128ade fix: Cloud Code trigger context vulnerable to prototype pollution (#10352) 2026-03-30 00:21:18 +01:00
Manuel f63fd1a3fe fix: LiveQuery protected-field guard bypass via array-like logical operator value ([GHSA-mmg8-87c5-jrc2](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmg8-87c5-jrc2)) (#10350) 2026-03-29 19:36:52 +01:00
Manuel 63c37c49c7 fix: Batch login sub-request rate limit uses IP-based keying (#10349) 2026-03-29 16:08:36 +01:00
Manuel 90802969fc fix: Session field immutability bypass via falsy-value guard ([GHSA-f6j3-w9v3-cq22](https://github.com/parse-community/parse-server/security/advisories/GHSA-f6j3-w9v3-cq22)) (#10347) 2026-03-29 04:55:39 +01:00
Manuel 8dd7bf2f61 feat: Add support for partialFilterExpression in MongoDB storage adapter (#10346) 2026-03-29 03:37:19 +01:00
Manuel f759bda075 fix: GraphQL complexity validator exponential fragment traversal DoS ([GHSA-mfj6-6p54-m98c](https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c)) (#10344) 2026-03-29 02:32:35 +01:00
Manuel dc59e27266 fix: Cloud function validator bypass via prototype chain traversal ([GHSA-vpj2-qq7w-5qq6](https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6)) (#10342) 2026-03-28 18:46:42 +00:00
Manuel 9c83e1a504 refactor: Bump path-to-regexp from 8.3.0 to 8.4.0 (#10340) 2026-03-28 16:39:54 +00:00
Manuel 705855cfa4 refactor: Bump jasmine from 5.7.1 to 6.1.0 (#10338) 2026-03-28 16:10:57 +00:00
Manuel 97921cbc5c refactor: Bump @semantic-release/github from 12.0.0 to 12.0.6 (#10337) 2026-03-27 20:03:29 +00:00
Manuel c717cc8667 refactor: Bump @apollo/server from 5.4.0 to 5.5.0 (#10336) 2026-03-27 18:03:06 +00:00
Manuel 4dd0d3d8be fix: GraphQL API endpoint ignores CORS origin restriction ([GHSA-q3p6-g7c4-829c](https://github.com/parse-community/parse-server/security/advisories/GHSA-q3p6-g7c4-829c)) (#10334) 2026-03-27 15:03:33 +00:00
Manuel 776c71c307 fix: LiveQuery protected field leak via shared mutable state across concurrent subscribers ([GHSA-m983-v2ff-wq65](https://github.com/parse-community/parse-server/security/advisories/GHSA-m983-v2ff-wq65)) (#10330) 2026-03-27 13:44:00 +00:00
Manuel e7efbebba3 fix: MFA single-use token bypass via concurrent authData login requests ([GHSA-w73w-g5xw-rwhf](https://github.com/parse-community/parse-server/security/advisories/GHSA-w73w-g5xw-rwhf)) (#10326) 2026-03-26 23:37:10 +00:00
Manuel 2be73d9d7b ci: Increase npm network timeout for Docker arm64 builds (#10325) 2026-03-26 21:04:27 +00:00
Manuel 770be86474 fix: Auth data exposed via verify password endpoint ([GHSA-wp76-gg32-8258](https://github.com/parse-community/parse-server/security/advisories/GHSA-wp76-gg32-8258)) (#10323) 2026-03-26 20:35:44 +00:00
Manuel f537e677f0 test: Fix flaky tests (#10320) 2026-03-26 02:20:57 +00:00
Manuel 92791c1d1d fix: Duplicate session destruction can cause unhandled promise rejection (#10319) 2026-03-26 01:41:45 +00:00
Manuel eea27af3b1 ci: Remove feature to retry flaky tests (#10314) 2026-03-26 00:30:55 +00:00
Manuel 3ff818034a refactor: Bump redis from 5.10.0 to 5.11.0 (#10317) 2026-03-25 23:56:19 +00:00
Manuel af23b92a34 refactor: Bump graphql from 16.11.0 to 16.13.2 (#10315) 2026-03-25 22:18:51 +00:00
Manuel cfbe7a04cc test: Fix flaky tests (#10313) 2026-03-25 19:20:55 +00:00
Manuel c5c43259d1 fix: Postgres query on non-existent column throws internal server error (#10308) 2026-03-25 00:07:06 +00:00
Manuel 3f888b1aac refactor: Bump follow-redirects from 1.15.9 to 1.15.11 (#10307) 2026-03-24 20:10:01 +00:00
Manuel 1bacddb1e4 refactor: Bump ws from 8.18.2 to 8.20.0 (#10306) 2026-03-24 19:48:06 +00:00
Manuel 0f3717d4ee refactor: Bump lru-cache from 11.2.6 to 11.2.7 (#10305) 2026-03-24 18:58:53 +00:00
Manuel f12804800b fix: Missing error messages in Parse errors (#10304) 2026-03-24 18:56:25 +00:00
Manuel fe9fba61dd test: Fix flaky test (#10303) 2026-03-24 15:52:45 +00:00
Manuel 6fcbb173d2 refactor: Bump lru-cache from 10.4.0 to 11.2.6 (#10302) 2026-03-24 15:41:17 +00:00
Manuel 9ec6f283a5 refactor: Bump semantic-release from 24.2.5 to 25.0.3 (#10297) 2026-03-24 03:01:04 +00:00
Manuel 1622f6af1c refactor: Bump lint-staged from 16.1.0 to 16.2.7 (#10296) 2026-03-24 02:04:23 +00:00
Manuel b344927b89 ci: Fix flaky GC tests (#10294) 2026-03-24 00:15:30 +00:00
Manuel c77330d5a7 refactor: Unnecessary deprecation warning on enableProductPurchaseLegacyApi: false (#10293) 2026-03-23 23:07:17 +00:00
Manuel 6449397e86 refactor: Bump express-rate-limit from 8.2.1 to 8.3.0 (#10292) 2026-03-23 22:56:25 +00:00
Manuel 7c8b213d96 fix: Maintenance key blocked from querying protected fields (#10290) 2026-03-23 03:50:45 +00:00