Commit Graph
5525 Commits
Author SHA1 Message Date
semantic-release-bot 1e0d6cee9b chore(release): 9.9.1-alpha.3 [skip ci]
## [9.9.1-alpha.3](https://github.com/parse-community/parse-server/compare/9.9.1-alpha.2...9.9.1-alpha.3) (2026-05-27)

### Bug Fixes

* Server option routeAllowList is bypassable through batch sub-requests ([GHSA-p84r-h6rx-f2xr](https://github.com/parse-community/parse-server/security/advisories/GHSA-p84r-h6rx-f2xr)) ([#10482](https://github.com/parse-community/parse-server/issues/10482)) ([552c6dd](https://github.com/parse-community/parse-server/commit/552c6dd754638c9f546fbceecd2ba0f7225a95d1))
9.9.1-alpha.3
2026-05-27 20:42:36 +00:00
Manuel 552c6dd754 fix: Server option routeAllowList is bypassable through batch sub-requests ([GHSA-p84r-h6rx-f2xr](https://github.com/parse-community/parse-server/security/advisories/GHSA-p84r-h6rx-f2xr)) (#10482) 2026-05-27 22:41:48 +02:00
Manuel 0ae0ed382b test: GraphQL endpoint is exempt from routeAllowList by design (#10480) 2026-05-27 00:36:20 +02:00
semantic-release-bot 828d0e0e45 chore(release): 9.9.1-alpha.2 [skip ci]
## [9.9.1-alpha.2](https://github.com/parse-community/parse-server/compare/9.9.1-alpha.1...9.9.1-alpha.2) (2026-05-18)

### Bug Fixes

* GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers ([GHSA-8cph-rgr4-g5vj](https://github.com/parse-community/parse-server/security/advisories/GHSA-8cph-rgr4-g5vj)) ([#10467](https://github.com/parse-community/parse-server/issues/10467)) ([155123a](https://github.com/parse-community/parse-server/commit/155123ade9bc88cdf4807cf267ea1196f9274773))
9.9.1-alpha.2
2026-05-18 15:05:52 +00:00
Manuel 155123ade9 fix: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers ([GHSA-8cph-rgr4-g5vj](https://github.com/parse-community/parse-server/security/advisories/GHSA-8cph-rgr4-g5vj)) (#10467) 2026-05-18 17:04:56 +02:00
semantic-release-bot 216cf8335b chore(release): 9.9.1-alpha.1 [skip ci]
## [9.9.1-alpha.1](https://github.com/parse-community/parse-server/compare/9.9.0...9.9.1-alpha.1) (2026-05-17)

### Bug Fixes

* Pre-authentication denial of service via client version header regex backtracking ([GHSA-38m6-82c8-4xfm](https://github.com/parse-community/parse-server/security/advisories/GHSA-38m6-82c8-4xfm)) ([#10463](https://github.com/parse-community/parse-server/issues/10463)) ([56c159e](https://github.com/parse-community/parse-server/commit/56c159ec962d729df09ccaa5cc2537751511e375))
9.9.1-alpha.1
2026-05-17 14:12:01 +00:00
Manuel 56c159ec96 fix: Pre-authentication denial of service via client version header regex backtracking ([GHSA-38m6-82c8-4xfm](https://github.com/parse-community/parse-server/security/advisories/GHSA-38m6-82c8-4xfm)) (#10463) 2026-05-17 15:11:10 +01:00
semantic-release-bot 4f90c5e107 chore(release): 9.9.0 [skip ci]
# [9.9.0](https://github.com/parse-community/parse-server/compare/9.8.0...9.9.0) (2026-05-01)

### Bug Fixes

* Context mutations leak across requests in `ParseServerRESTController` ([#10291](https://github.com/parse-community/parse-server/issues/10291)) ([60a58ec](https://github.com/parse-community/parse-server/commit/60a58ec11a8bb67aaf217b1e7362b89d742b66da))
* MFA SMS one-time password accepted twice under concurrent login ([GHSA-jpq4-7fmq-q5fj](https://github.com/parse-community/parse-server/security/advisories/GHSA-jpq4-7fmq-q5fj)) ([#10448](https://github.com/parse-community/parse-server/issues/10448)) ([725be0d](https://github.com/parse-community/parse-server/commit/725be0d602baa619492606e7b3f6829082d93a4c))

### Features

* Add `rawValues` and `rawFieldNames` options for aggregation queries ([#10438](https://github.com/parse-community/parse-server/issues/10438)) ([f26700e](https://github.com/parse-community/parse-server/commit/f26700e39d1980940467bee0d26ca3deb88e3924))
* Add installation deviceToken deduplication options ([#10451](https://github.com/parse-community/parse-server/issues/10451)) ([9fee1a0](https://github.com/parse-community/parse-server/commit/9fee1a07080ab8bda2a3d4798881bcc288e5b37a))
9.9.0
2026-05-01 12:15:41 +00:00
Manuel eb6441362a build: Release (#10452) 2026-05-01 13:14:53 +01:00
GitHub Actions 6667900f94 empty commit to trigger CI 2026-05-01 00:37:57 +00:00
semantic-release-bot 50c37a4ea3 chore(release): 9.9.0-alpha.3 [skip ci]
# [9.9.0-alpha.3](https://github.com/parse-community/parse-server/compare/9.9.0-alpha.2...9.9.0-alpha.3) (2026-04-30)

### Features

* Add installation deviceToken deduplication options ([#10451](https://github.com/parse-community/parse-server/issues/10451)) ([9fee1a0](https://github.com/parse-community/parse-server/commit/9fee1a07080ab8bda2a3d4798881bcc288e5b37a))
9.9.0-alpha.3
2026-04-30 22:12:36 +00:00
Manuel 9fee1a0708 feat: Add installation deviceToken deduplication options (#10451) 2026-04-30 23:11:39 +01:00
semantic-release-bot 35207c2796 chore(release): 9.9.0-alpha.2 [skip ci]
# [9.9.0-alpha.2](https://github.com/parse-community/parse-server/compare/9.9.0-alpha.1...9.9.0-alpha.2) (2026-04-26)

### Bug Fixes

* MFA SMS one-time password accepted twice under concurrent login ([GHSA-jpq4-7fmq-q5fj](https://github.com/parse-community/parse-server/security/advisories/GHSA-jpq4-7fmq-q5fj)) ([#10448](https://github.com/parse-community/parse-server/issues/10448)) ([725be0d](https://github.com/parse-community/parse-server/commit/725be0d602baa619492606e7b3f6829082d93a4c))
9.9.0-alpha.2
2026-04-26 02:11:20 +00:00
Manuel 725be0d602 fix: MFA SMS one-time password accepted twice under concurrent login ([GHSA-jpq4-7fmq-q5fj](https://github.com/parse-community/parse-server/security/advisories/GHSA-jpq4-7fmq-q5fj)) (#10448) 2026-04-26 03:10:27 +01:00
semantic-release-bot 0980ab1a40 chore(release): 9.9.0-alpha.1 [skip ci]
# [9.9.0-alpha.1](https://github.com/parse-community/parse-server/compare/9.8.1-alpha.1...9.9.0-alpha.1) (2026-04-17)

### Features

* Add `rawValues` and `rawFieldNames` options for aggregation queries ([#10438](https://github.com/parse-community/parse-server/issues/10438)) ([f26700e](https://github.com/parse-community/parse-server/commit/f26700e39d1980940467bee0d26ca3deb88e3924))
9.9.0-alpha.1
2026-04-17 08:13:09 +00:00
Manuel f26700e39d feat: Add rawValues and rawFieldNames options for aggregation queries (#10438) 2026-04-17 09:12:18 +01:00
Manuel fc53270dbe test: Fix socket hang up in node-fetch 3.3.2 fails tests (#10443) 2026-04-17 01:39:53 +01:00
Manuel f303f752c6 refactor: Bump node-fetch from 3.2.10 to 3.3.2 (#10441) 2026-04-17 01:52:11 +02:00
Manuel 163d7be605 refactor: Bump jsonwebtoken from 9.0.2 to 9.0.3 (#10440) 2026-04-17 01:19:05 +02:00
Manuel cbd1da7be3 refactor: Bump path-to-regexp from 8.4.0 to 8.4.2 (#10439) 2026-04-16 13:39:55 +02:00
semantic-release-bot 31f70a3269 chore(release): 9.8.1-alpha.1 [skip ci]
## [9.8.1-alpha.1](https://github.com/parse-community/parse-server/compare/9.8.0...9.8.1-alpha.1) (2026-04-12)

### Bug Fixes

* Context mutations leak across requests in `ParseServerRESTController` ([#10291](https://github.com/parse-community/parse-server/issues/10291)) ([60a58ec](https://github.com/parse-community/parse-server/commit/60a58ec11a8bb67aaf217b1e7362b89d742b66da))
9.8.1-alpha.1
2026-04-12 14:21:46 +00:00
Yogendra Singh 60a58ec11a fix: Context mutations leak across requests in ParseServerRESTController (#10291) 2026-04-12 15:20:58 +01:00
semantic-release-bot 7c3b43d263 chore(release): 9.8.0 [skip ci]
# [9.8.0](https://github.com/parse-community/parse-server/compare/9.7.0...9.8.0) (2026-04-12)

### Bug Fixes

* Bump lodash from 4.17.23 to 4.18.1 ([#10393](https://github.com/parse-community/parse-server/issues/10393)) ([19716ad](https://github.com/parse-community/parse-server/commit/19716ad9afe9400ad2440c0ed3c5fbfe376a8585))
* Endpoint `/sessions/me` bypasses `_Session` `protectedFields` ([GHSA-g4v2-qx3q-4p64](https://github.com/parse-community/parse-server/security/advisories/GHSA-g4v2-qx3q-4p64)) ([#10406](https://github.com/parse-community/parse-server/issues/10406)) ([d507575](https://github.com/parse-community/parse-server/commit/d5075758f6c3ae9d806671de196fd8b419bc517e))
* Endpoint `/upgradeToRevocableSession` ignores `_Session` `protectedFields` ([#10408](https://github.com/parse-community/parse-server/issues/10408)) ([c136e2b](https://github.com/parse-community/parse-server/commit/c136e2b7ab74609a5127fb68fc5ba40fef440f48))
* Endpoints `/login` and `/verifyPassword` ignore `_User` `protectedFields` ([#10409](https://github.com/parse-community/parse-server/issues/10409)) ([8a3db3b](https://github.com/parse-community/parse-server/commit/8a3db3b9666ea998a8843c629e1af55b105e22e0))
* Facebook Standard Login missing app ID validation ([#10429](https://github.com/parse-community/parse-server/issues/10429)) ([fd31159](https://github.com/parse-community/parse-server/commit/fd31159859ed90f57eb3713f82c9f5b04b20a28c))
* File upload Content-Type override via extension mismatch ([GHSA-vr5f-2r24-w5hc](https://github.com/parse-community/parse-server/security/advisories/GHSA-vr5f-2r24-w5hc)) ([#10383](https://github.com/parse-community/parse-server/issues/10383)) ([dd7cc41](https://github.com/parse-community/parse-server/commit/dd7cc41a952b9ec6fa655a5655f106cca27d65c7))
* Login timing side-channel reveals user existence ([GHSA-mmpq-5hcv-hf2v](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmpq-5hcv-hf2v)) ([#10398](https://github.com/parse-community/parse-server/issues/10398)) ([531b9ab](https://github.com/parse-community/parse-server/commit/531b9ab6dda4268ede365367fcdc6d98e737ccc3))
* Maintenance key IP mismatch silently downgrades to regular auth instead of rejecting ([#10391](https://github.com/parse-community/parse-server/issues/10391)) ([7d8b367](https://github.com/parse-community/parse-server/commit/7d8b367e0b3ef9e9dd6735408068895ead873a0c))
* Master key does not bypass `protectedFields` on various endpoints ([#10412](https://github.com/parse-community/parse-server/issues/10412)) ([c0889c8](https://github.com/parse-community/parse-server/commit/c0889c8575ee6c6ee01c79cd1ae457124e2a08b3))
* Nested batch sub-requests cause unclear error ([#10371](https://github.com/parse-community/parse-server/issues/10371)) ([6635096](https://github.com/parse-community/parse-server/commit/66350964c8a200eb9e4540f6fcdc0fe0099c5ff6))
* Session field guard bypass via falsy values for ACL and user fields ([#10382](https://github.com/parse-community/parse-server/issues/10382)) ([ead12bd](https://github.com/parse-community/parse-server/commit/ead12bd1df7f11013d9266e41014dcb143351341))
* Streaming file download bypasses afterFind file trigger authorization ([GHSA-hpm8-9qx6-jvwv](https://github.com/parse-community/parse-server/security/advisories/GHSA-hpm8-9qx6-jvwv)) ([#10361](https://github.com/parse-community/parse-server/issues/10361)) ([a0b0c69](https://github.com/parse-community/parse-server/commit/a0b0c69fc44f87f80d793d257344e7dcbf676e22))

### Features

* Add `requestComplexity.allowRegex` option to disable `$regex` query operator ([#10418](https://github.com/parse-community/parse-server/issues/10418)) ([18482e3](https://github.com/parse-community/parse-server/commit/18482e386c1e723da2df3137f61fa5e2bc8983a6))
* Add `requestComplexity.subqueryLimit` option to limit subquery results ([#10420](https://github.com/parse-community/parse-server/issues/10420)) ([bf40004](https://github.com/parse-community/parse-server/commit/bf40004d258f114c06a3085052ca094384b52b43))
* Add route block with new server option `routeAllowList` ([#10389](https://github.com/parse-community/parse-server/issues/10389)) ([f2d06e7](https://github.com/parse-community/parse-server/commit/f2d06e7b95242268607bfa5205b4e86ba7c7698e))
* Add server option `fileDownload` to restrict file download ([#10394](https://github.com/parse-community/parse-server/issues/10394)) ([fc117ef](https://github.com/parse-community/parse-server/commit/fc117efa4dc233ad6dfee6f46d80991b10927ba8))
* Add support for invoking Cloud Function with `multipart/form-data` protocol ([#10395](https://github.com/parse-community/parse-server/issues/10395)) ([a3f36a2](https://github.com/parse-community/parse-server/commit/a3f36a2ddb981d9868ddf26b128e24b2d58214bd))
9.8.0
2026-04-12 10:26:31 +00:00
Manuel b3dedd0482 build: Release (#10430) 2026-04-12 11:25:40 +01:00
GitHub Actions 1464b8c582 empty commit to trigger CI 2026-04-12 00:21:42 +00:00
semantic-release-bot 2998532966 chore(release): 9.8.0-alpha.13 [skip ci]
# [9.8.0-alpha.13](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.12...9.8.0-alpha.13) (2026-04-12)

### Bug Fixes

* Facebook Standard Login missing app ID validation ([#10429](https://github.com/parse-community/parse-server/issues/10429)) ([fd31159](https://github.com/parse-community/parse-server/commit/fd31159859ed90f57eb3713f82c9f5b04b20a28c))
9.8.0-alpha.13
2026-04-12 00:17:00 +00:00
Manuel fd31159859 fix: Facebook Standard Login missing app ID validation (#10429) 2026-04-12 01:16:11 +01:00
Manuel 39af946200 refactor: Bump @babel/cli from 7.27.0 to 7.28.6 (#10424) 2026-04-10 21:45:42 +01:00
Manuel 8b80e55afd refactor: Bump otpauth from 9.4.0 to 9.5.0 (#10423) 2026-04-10 21:22:07 +01:00
Manuel b55880d702 refactor: Bump typescript-eslint from 8.53.1 to 8.58.0 (#10422) 2026-04-10 20:51:40 +01:00
semantic-release-bot 406a92743b chore(release): 9.8.0-alpha.12 [skip ci]
# [9.8.0-alpha.12](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.11...9.8.0-alpha.12) (2026-04-10)

### Features

* Add `requestComplexity.subqueryLimit` option to limit subquery results ([#10420](https://github.com/parse-community/parse-server/issues/10420)) ([bf40004](https://github.com/parse-community/parse-server/commit/bf40004d258f114c06a3085052ca094384b52b43))
9.8.0-alpha.12
2026-04-10 15:50:28 +00:00
Manuel bf40004d25 feat: Add requestComplexity.subqueryLimit option to limit subquery results (#10420) 2026-04-10 16:49:34 +01:00
semantic-release-bot df5e97fd40 chore(release): 9.8.0-alpha.11 [skip ci]
# [9.8.0-alpha.11](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.10...9.8.0-alpha.11) (2026-04-09)

### Features

* Add `requestComplexity.allowRegex` option to disable `$regex` query operator ([#10418](https://github.com/parse-community/parse-server/issues/10418)) ([18482e3](https://github.com/parse-community/parse-server/commit/18482e386c1e723da2df3137f61fa5e2bc8983a6))
9.8.0-alpha.11
2026-04-09 17:13:01 +00:00
Manuel 18482e386c feat: Add requestComplexity.allowRegex option to disable $regex query operator (#10418) 2026-04-09 18:12:12 +01:00
Antoine Cormouls f208037b3b refactor: Replace uuid dependency with native UUID (#10416) 2026-04-08 14:17:24 +01:00
Manuel d7d5ae56f7 test: Fix flaky LiveQuery tests caused by session token leak (#10415) 2026-04-08 00:36:45 +01:00
Manuel 7d4a4607fa test: LiveQuery disconnect does not clear subscription info (#10414) 2026-04-08 00:11:55 +01:00
semantic-release-bot f184f76bce chore(release): 9.8.0-alpha.10 [skip ci]
# [9.8.0-alpha.10](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.9...9.8.0-alpha.10) (2026-04-07)

### Bug Fixes

* Master key does not bypass `protectedFields` on various endpoints ([#10412](https://github.com/parse-community/parse-server/issues/10412)) ([c0889c8](https://github.com/parse-community/parse-server/commit/c0889c8575ee6c6ee01c79cd1ae457124e2a08b3))
9.8.0-alpha.10
2026-04-07 12:49:34 +00:00
Manuel c0889c8575 fix: Master key does not bypass protectedFields on various endpoints (#10412) 2026-04-07 13:48:39 +01:00
semantic-release-bot 32680e3046 chore(release): 9.8.0-alpha.9 [skip ci]
# [9.8.0-alpha.9](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.8...9.8.0-alpha.9) (2026-04-07)

### Bug Fixes

* Endpoints `/login` and `/verifyPassword` ignore `_User` `protectedFields` ([#10409](https://github.com/parse-community/parse-server/issues/10409)) ([8a3db3b](https://github.com/parse-community/parse-server/commit/8a3db3b9666ea998a8843c629e1af55b105e22e0))
9.8.0-alpha.9
2026-04-07 12:02:01 +00:00
Manuel 8a3db3b966 fix: Endpoints /login and /verifyPassword ignore _User protectedFields (#10409) 2026-04-07 13:01:11 +01:00
semantic-release-bot 57a4fba827 chore(release): 9.8.0-alpha.8 [skip ci]
# [9.8.0-alpha.8](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.7...9.8.0-alpha.8) (2026-04-07)

### Bug Fixes

* Endpoint `/upgradeToRevocableSession` ignores `_Session` `protectedFields` ([#10408](https://github.com/parse-community/parse-server/issues/10408)) ([c136e2b](https://github.com/parse-community/parse-server/commit/c136e2b7ab74609a5127fb68fc5ba40fef440f48))
9.8.0-alpha.8
2026-04-07 09:10:02 +00:00
Manuel c136e2b7ab fix: Endpoint /upgradeToRevocableSession ignores _Session protectedFields (#10408) 2026-04-07 10:09:09 +01:00
semantic-release-bot 8b19852ff2 chore(release): 9.8.0-alpha.7 [skip ci]
# [9.8.0-alpha.7](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.6...9.8.0-alpha.7) (2026-04-06)

### Bug Fixes

* Endpoint `/sessions/me` bypasses `_Session` `protectedFields` ([GHSA-g4v2-qx3q-4p64](https://github.com/parse-community/parse-server/security/advisories/GHSA-g4v2-qx3q-4p64)) ([#10406](https://github.com/parse-community/parse-server/issues/10406)) ([d507575](https://github.com/parse-community/parse-server/commit/d5075758f6c3ae9d806671de196fd8b419bc517e))
9.8.0-alpha.7
2026-04-06 16:47:25 +00:00
Manuel d5075758f6 fix: Endpoint /sessions/me bypasses _Session protectedFields ([GHSA-g4v2-qx3q-4p64](https://github.com/parse-community/parse-server/security/advisories/GHSA-g4v2-qx3q-4p64)) (#10406) 2026-04-06 17:46:32 +01:00
Manuel 9168e69cb7 test: Webhook overwrites Cloud Code function warning (#10400) 2026-04-05 22:08:12 +01:00
semantic-release-bot 6322aab48d chore(release): 9.8.0-alpha.6 [skip ci]
# [9.8.0-alpha.6](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.5...9.8.0-alpha.6) (2026-04-05)

### Bug Fixes

* Login timing side-channel reveals user existence ([GHSA-mmpq-5hcv-hf2v](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmpq-5hcv-hf2v)) ([#10398](https://github.com/parse-community/parse-server/issues/10398)) ([531b9ab](https://github.com/parse-community/parse-server/commit/531b9ab6dda4268ede365367fcdc6d98e737ccc3))
9.8.0-alpha.6
2026-04-05 16:49:42 +00:00
Manuel 531b9ab6dd fix: Login timing side-channel reveals user existence ([GHSA-mmpq-5hcv-hf2v](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmpq-5hcv-hf2v)) (#10398) 2026-04-05 17:48:57 +01:00
Manuel f7f354226e ci: Replace third-party GitHub Actions with trusted alternatives (#10397) 2026-04-04 20:00:25 +01:00
semantic-release-bot 21358e6f7c chore(release): 9.8.0-alpha.5 [skip ci]
# [9.8.0-alpha.5](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.4...9.8.0-alpha.5) (2026-04-04)

### Features

* Add support for invoking Cloud Function with `multipart/form-data` protocol ([#10395](https://github.com/parse-community/parse-server/issues/10395)) ([a3f36a2](https://github.com/parse-community/parse-server/commit/a3f36a2ddb981d9868ddf26b128e24b2d58214bd))
9.8.0-alpha.5
2026-04-04 16:47:43 +00:00