Skip to content

Upload SP 11.12.2 RNs#11599

Open
ConnorLand wants to merge 5 commits into
developmentfrom
ctl-add-SP-11.12.2-RNs
Open

Upload SP 11.12.2 RNs#11599
ConnorLand wants to merge 5 commits into
developmentfrom
ctl-add-SP-11.12.2-RNs

Conversation

@ConnorLand

Copy link
Copy Markdown
Collaborator

No description provided.

#### Other Improvements

- We improved the security of the module import process by validating the file paths declared in an MPK package before extraction. Packages containing paths that traverse outside the app directory or target protected directories (such as `.git`, `deployment`, or `releases`) are now rejected with an error.
- We fixed a bypass in the extraction-time path filter where non-canonical ZIP entry names (e.g. paths containing `..` segments) could evade the protected-subtree check. Entry names are now canonicalized before filtering.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Mendix.Latin] Use 'for example, ' instead of 'e.g. '.

- We fixed an issue where renaming a document would not update its name in the Maia changes list.
- We fixed an issue where the Change Data Capture service was allowing the addition of inherited attributes and associations when this is not supported.
- We fixed an issue where Studio Pro appeared to freeze briefly when opening an app. The progress dialog now covers the full loading process.
- we fixed the orientation issue in native datepicker widget for ios, supporting landscape orientation.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Mendix.Capitalization] Use ''iOS'' (capitalized)

- we fixed the orientation issue in native datepicker widget for ios, supporting landscape orientation.
- We changed the consistency check for offline Create and Change actions involving entities with AutoNumber or Calculated attributes from a hard error to a warning. The warning reminds you that AutoNumber values will default to `0` until the next synchronization, and Calculated attribute values will not be evaluated offline.
- We fixed an issue where local file storage does not use optimal directory structure.
- We fixed an issue where downloading a marketplace module with Maia resulted in the name of the module being displayed in the version field. This is now resolved.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Mendix.Capitalization] Use ''Marketplace'' (capitalized)

ConnorLand and others added 4 commits July 23, 2026 15:07
even though they have workarounds, they don't have fixes yet
Capitalism at its finest
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants