Hotfix release

  • 0033402: [api rest] Updating an Issue through the API sets all comments last edit timestamp (community)
  • 0033404: [authorization] Unable to grant user access to private issue by adding them as a monitoring user (atrol)
  • 0033248: [custom fields] APPLICATION ERROR 2800 Invalid form security token when trying to delete custom field (dregad)
  • 0033358: [custom fields] Custom fields are showing when resolving issues form despite not checking the option (atrol)
  • 0033372: [db mssql] SQL error opening Manage Users page with MSSQL (dregad)
  • 0033374: [other] Erratic behavior of RestProjectVersionTest::testProjectUpdateVersion PHPUnit test case (dregad)
  • 0033171: [db schema] Update ADOdb to 5.22.7 (dregad)
  • 0033173: [api rest] No endpoints working on Windows server with PHP 8.1+ (dregad)
6 of 8 issue(s) resolved View Issues

Feature and maintenance release. Dropping support for PHP 7.3 and older.

  • 0024689: [administration] Remove clickable alphanumeric index in manage_user_page.php
  • 0026599: [db schema] Behavioural changes for BLOBs in ADOdb 5.21
  • 0020577: [plug-ins] Consistent use of EVENT_UPDATE_BUG_DATA
  • 0021908: [security] Weakened security headers in 2.0.x
  • 0031699: [api rest] Upgrade Slim Framework to 4.x
  •        0032808: [installation] Increase minimum PHP requirement to 7.4 (dregad)
  • 0033007: [code cleanup] Remove deprecated and incorrect usage of Pragma: no-cache header (dregad)
  • 0033098: [tools] Ugrade to PHPUnit 9.6 and adapt test suite (dregad)
  •        0032808: [installation] Increase minimum PHP requirement to 7.4 (dregad)
  • 0032470: [api rest] REST API: Project Category Add/Update/Delete (vboctor)
  • 0017577: [performance] Improve print_user_option_list() performance (dregad)
  • 0032489: [documentation] Document impersonation of users via REST API (vboctor)
  • 0030047: [bugtracker] After login with HTTP_AUTH user is redirected to "main_page.php" (dregad)
  • 0027807: [bugtracker] Prevent silent update of invalid enum fields when editing issue (dregad)
  • 0032577: [api rest] Get Issues should return total count of issues for pagination (vboctor)
  • 0027572: [administration] Improve management of failed logins and locked accounts (atrol)
  • 0026929: [api rest] Support user account unlock via REST API (dregad)
  • 0028831: [ui] Improve date filter fields display (label and "no filter" text) (dregad)
  • 0024241: [markdown] $g_html_valid_tags are not rendered if Markdown is enabled (dregad)
  • 0008141: [bugtracker] Issue reporters should be able to update their own issues (atrol)
  • 0019964: [authentication] Wrong anonymous rights application (dregad)
  • 0020307: [printing] Print issue page needs to adjust formatting for tags and relationship handler (vboctor)
  • 0020540: [attachments] Implement upgrade step to cleanup corrupt disk attachments after db->disk conversion (dregad)
  • 0020431: [db schema] Use utf8mb4 charset for new MySQL installations (dregad)
  • 0020874: [ui] Content Security Policy blocked embedded images added by Chrome Extension (vboctor)
  • 0021694: [ui] inconsistent presentation of required fields (syncguru)
  • 0022464: [custom fields] Loose type comparison can prevent custom field update (dregad)
  • 0022839: [authentication] Deprecate MD5 login method and replace with BCRYPT hash (dregad)
  • 0022840: [authentication] Don't expire user sessions when updating password hash after login method change (dregad)
  • 0022841: [authentication] Don't truncate password when it exceeds db field size (dregad)
  • 0024188: [ui] Update issue history code to display user names via standard APIs
  • 0022408: [custom fields] Custom field's value logged as changed in history, when it wasn't changed (vboctor)
  • 0032998: [administration] Call to undefined function mci_get_project_id() when removing a user from a project (vboctor)
  • 0033019: [api rest] X-Mantis-Version headers sent when REST API is disabled (dregad)
  • 0024628: [markdown] Double quotes " and lesser than sign < are shown as HTML entity within Markdown code blocks (dregad)
  • 0033012: [administration] Don't abort Admin Checks after first failure unless it's critical (dregad)
  • 0033373: [other] Update HTML Purifier to 4.17.0 (dregad)
2 of 36 issue(s) resolved View Issues