Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 35 additions & 0 deletions src/content/docs/docs/getting-started/releases.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,41 @@ sidebar:

## Version 7


### v7.10.0

#### Global password, WebP, Video loop and security fixes

What? A new release already? How comes? Well... @WojciechCiemski has been busy poking small holes in our code, and we gotta patch them up.

However, this does not mean that the release is only about fixes; we also have some exciting new features to share. For starters, we added
the possibility to set a global password on your full Lychee instance. Done with having the same password for each albums, one password to rule them all.
Of course, if you have an account, you can always login directly and bypass the screen.

We also have our first contribution from @NikitaTH. They added the possibility to configure the amount of compression on the size variants and also the support
for WebP format. This is disabled by default to keep the existing behavior. Just know that it is now an option.

We got a small request to add support for the video loop attribute, which has now been implemented. Furthermore, due to the discoveries for @WojciechCiemski,
we have decided to separate the EDIT rights from the MOVE rights. A smart user with EDIT rights in an album without the full size access could move the photos
to an album they owned and thus gained access to the original. Fun trick right? So to fix this, we added the CAN_MOVE rights which is now required to move/merge albums (and photos). We also tighten the requirement on the destinations albums. This makes the permissions a bit stricter so that users cannot bypass restrictions as easily.

* `new` #4799 : Global password gallery setting by @ildyria.
* `new` #4790 : Configurable size variant format (WebP) and lossless quality by @NikitaTH.
* `new` #4787 : Add CAN_MOVE rights by @ildyria.
* `new` #4807 : Add support for video loop attribute by @ildyria.
* `fix` #4789 : Strip completely at the php level to avoid xss by @ildyria.
* `fix` #4791 : block all IPv6-transition spellings that embed an internal IPv4 by @anzal1.
* `fix` #4798 : Fixes advisories crash when on internal network without internet access by @ildyria.
* `fix` #4804 : Avoid XSS in GPX tracks by @ildyria.
* `fix` #4806 : Fix dock being visible when user has not edit rights by @ildyria.
* `fix` #4805 : Avoid uploading a picture of another user and getting extra perks by @ildyria.
* `fix` #4808 : Fix video player? by @ildyria.

#### New Contributors
* @anzal1 made their first contribution in https://github.com/LycheeOrg/Lychee/pull/4791
* @NikitaTH made their first contribution in https://github.com/LycheeOrg/Lychee/pull/4790


### v7.9.0

Released on September 25th, 2026
Expand Down
1 change: 1 addition & 0 deletions src/data/releases.ts
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ export interface Release {

// Release data extracted from releases.md
export const releases: Release[] = [
{ version: 'v7.10.0', date: 'Sep 29, 2026', title: 'Global password, WebP, Video loop and security fixes', type: 'feature', highlights: ['Global password gallery setting', 'Configurable size variant format (WebP) and lossless quality', 'Various security and bug fixes'] },
{ version: 'v7.9.0', date: 'Sep 25, 2026', title: 'Features and fixes', type: 'feature', highlights: ['Added support for S3 object prefixes', 'Kanidm OAuth Provider', 'Setting to show highest-quality image in full-screen viewer'] },
{ version: 'v7.8.5', date: 'Sep 18, 2026', title: 'Fixes', type: 'bugfix', highlights: ['Fixes translations not applied'] },
{ version: 'v7.8.4', date: 'Sep 17, 2026', title: 'Fixes', type: 'bugfix', highlights: ['Cover for locked albums', 'improved embeddings'] },
Expand Down
7 changes: 7 additions & 0 deletions src/pages/support.astro
Original file line number Diff line number Diff line change
Expand Up @@ -424,6 +424,13 @@ const metadata = {
alt: 'adrbogacz',
},
},
{
title: 'anzal1 (Anzal Husain Abidi)',
image: {
src:'https://avatars.githubusercontent.com/u/77688078?v=4',
alt: 'anzal1'
Comment thread
ildyria marked this conversation as resolved.
}
}
]}
/>

Expand Down
Loading