Release Notes - XWiki Platform - Version 5.4.5 - HTML format

Bug

  • [XWIKI-5155] - HTTP header injection via xredirect
  • [XWIKI-9544] - Activity Stream should not show deleted documents that was hidden.
  • [XWIKI-9551] - When you delete a user from the main wiki it is not deleted from the subwiki groups
  • [XWIKI-9981] - Clicking on the "Change password" button discards all your other profile modifications
  • [XWIKI-10182] - Protect against URL used as extension author which lead to large stack trace in XWiki logs
  • [XWIKI-10220] - Wiki Creation Wizard step buttons aren't translated
  • [XWIKI-10239] - LogEvent events should not be sent through the cluster
  • [XWIKI-10240] - Download is stuck when choosing XAR as output and leaving the Target field empty on Jetty 8.1.9
  • [XWIKI-10242] - Generated URLs always contain WebHome in the path
  • [XWIKI-10246] - Whatever happen when saving backlinks it should never break the document save
  • [XWIKI-10250] - Livetables don't display document titles depending on XWiki's UI language
  • [XWIKI-10251] - Build of xwiki-platform breaks with wrong locale
  • [XWIKI-10261] - Solr "Creator" facet title does not get translated
  • [XWIKI-10279] - Global users are not suggested when trying to send them a message from a subwiki
  • [XWIKI-10286] - XWiki#exists returns false for document translations
  • [XWIKI-10289] - "java.lang.IllegalArgumentException: Comparison method violates its general contract!" on Java 7
  • [XWIKI-10290] - Empty HQL query throws exception
  • [XWIKI-10291] - Formulas are not showing up in PDF documents if document is not public
  • [XWIKI-10315] - Programming right does not imply wiki create right
  • [XWIKI-10320] - New XSS in the user profile
  • [XWIKI-10326] - XSS/Phishing vulnerability in the attachment selector
  • [XWIKI-10328] - Authentication cookies should be marked as Secure
  • [XWIKI-10337] - Wysiwyg scroll bar gets blocked on IE11
  • [XWIKI-10338] - Static list values are not properly localized in an AWM application
  • [XWIKI-10351] - Groups with '+' - symbol can't be deleted

Improvement

  • [XWIKI-10238] - Set context user as author/creator when the Confluence package does not contain any author/creator
  • [XWIKI-10268] - SOLR startup sychronization should use less requests
  • [XWIKI-10284] - User Directory should not show full XWiki username

Edit/Copy Release Notes

The text area below allows the project release notes to be edited and copied to another document.