Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions src/content/docs/index.mdoc
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,8 @@ description: Learn what FOSSBilling is, where to start, and how to get involved
tableOfContents: false
banner:
content: |
<strong>0.8.7 is here!</strong> Check out the
<a href="https://github.com/FOSSBilling/FOSSBilling/releases/tag/0.8.7">release notes</a>
<strong>0.8.8 is here!</strong> Check out the
<a href="https://github.com/FOSSBilling/FOSSBilling/releases/tag/0.8.8">release notes</a>
and <a href="/maintenance/updating/0-7-to-0-8/">0.7 → 0.8 upgrade guide</a> for details.
---

Expand Down
26 changes: 26 additions & 0 deletions src/content/docs/maintenance/Updating/0-7-to-0-8.mdoc
Original file line number Diff line number Diff line change
Expand Up @@ -550,6 +550,32 @@ The bundled JavaScript API wrapper (`js/api.js`) already handles the new name, s
- Staff and client listing responses no longer include password hashes or API tokens.
- Payment gateway and domain registrar secrets are now masked in API responses and admin forms. Admins see a "Configured" badge instead of the raw value, and leaving a field blank preserves the existing secret.

## Escaping, Cron & Payment Hardening (0.8.8)

{% aside type="caution" %}
**0.8.8 is a security release** hardening payment handling, checkout, and session management. Update as soon as possible.
{% /aside %}

### Breaking: Stored Escaping

Stored values are no longer HTML-escaped before saving; escaping now happens at the rendering boundary, and a database patch repairs rows that were previously stored double-escaped. If your custom themes or modules pre-escape output or rely on stored escaped values, verify their rendering after updating.

### Cron Entry Point Now CLI-Only

The `cron.php` entry point now refuses non-CLI execution, closing direct HTTP triggering of the scheduler script. If you triggered `cron.php` over HTTP, switch to a system cron job or to the hash-protected guest cron endpoint (`guest/cron/run`) when enabled in **System → Cron**.

### Sessions

Admin and client sessions are now invalidated when API tokens are rotated, matching the existing password-change behavior.

### Payment Gateway Hardening

PayPal notifications are bound to their invoice with signed callback URLs, Stripe redirect PaymentIntents are verified for ownership and currency before applying, PayPal IPN currencies are validated, and gateway cancellations are restricted to the stored subscription. This is transparent unless you maintain a custom payment gateway — test payments, refunds, and cancellations after updating.

### Addon Quantity Selection

Addons now support quantity selection: the requested quantity is validated against the addon's flag and stored on the addon order, with an order-form quantity input and admin toggles. Review addon configurations after updating if you sell quantity-based addons.

## Deprecations & Removals (Summary)

| Component | Status | Notes |
Expand Down
13 changes: 13 additions & 0 deletions src/content/docs/maintenance/changelog.mdoc
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,19 @@ FOSSBilling publishes release notes and tagged versions on GitHub. Use the links

For the latest changes, start with the [most recent release](https://github.com/FOSSBilling/FOSSBilling/releases/latest).

### Version 0.8.8

| Area | Summary |
|------|---------|
| **Breaking** | Stored values are no longer HTML-escaped before saving; escaping now happens at render time, with a database patch repairing previously double-escaped rows. Custom themes or modules that pre-escape output or rely on stored escaped values should verify rendering. |
| **Security** | PayPal notifications bound to their invoice with signed callback URLs; Stripe redirect PaymentIntent ownership and currency verified before applying; PayPal IPN currency validated; gateway cancellations restricted to the stored subscription; once-per-client promo race, client-bound email recipient, reCAPTCHA v3 fast-submit bypass, and signup quota fixes; admin and client sessions invalidated on API token rotation; promo history and order/ticket details exposure limited; `cron.php` now refuses non-CLI execution (use the hash-protected guest cron endpoint when enabled in System → Cron instead); theme config directories protected; installer removed from production debug builds. |
| **New Features** | Addon quantity selection with validation, storage on the addon order, order-form input, and admin toggles. |
| **Enhancements** | Open hosting plan limits shown as "Unlimited"; domain transfers through the Email and Custom registrars; transfer codes collected for hosting domain orders. |
| **Bug Fixes** | Client signup CAPTCHA double-verification; multi-item cart orders missing from client list; invoice PDF failure on missing company address; `Server_Manager::getPasswordLength()` cron fatal; promo redemption `serie_nr` column; restored product quantity toggle; Namecheap nameservers and Plesk credential preservation; renewal, balance, Add Funds deposit, ticket, gateway, tax math, and theme CSS fixes. |
| **Changes** | Template-cache write failures render an error page instead of a raw 500; cache-backend configuration errors surfaced as settings-form validation errors. |

[View the full 0.8.8 release notes](https://github.com/FOSSBilling/FOSSBilling/releases/tag/0.8.8) for the complete list of changes.

### Version 0.8.7

| Area | Summary |
Expand Down
Loading