Firefly III is een in PHP geschreven webapplicatie waarmee een overzicht van je financiën kan worden bijgehouden. Het kan de data importeren vanuit csv-bestanden, de GoCardless-api of de Spectre-api. Voor meer informatie over dit programma verwijzen we naar deze pagina. De ontwikkelaar loopt ook op Tweakers rond en bespreekt zijn applicatie in het grote 'Firefly III'-topic. Versie 6.7.1 is uitgekomen en hier zijn de volgende veranderingen en verbeteringen in aangebracht:
Known issuesAdded
- Editing and creating split transactions may sometimes mix up the order of the splits. The data itself is never mixed up however.
- Some user managed to get a PR co-authored by Claude past my eagle eyes. Sorry about that. Luckily just a small fix.
- Many small and large usability issues still exist in the new layout. My humble apologies. I could not catch them all (sad Pikachu face).
Changed
- Added a view for all transactions.
Removed
- oAuth tokens are now on a separate page.
- The rule engine features an "expression engine". It is now disabled by default and must be turned on again in
/settings.- Switched from Twig template engine to Blade.
- Introduced a new version of the AdminLTE template.
- Introduces new forms for creating and editing transactions
- Switched from Font Awesome to Bootstrap Icons
- Login page now no longer advertises it's Firefly III
- Cron jobs are now per user, only users with the "owner" role can force the cron job or run it for different users.
Fixed
- Old forms, old code, old images.
Security
- Issue 10652 (Handling split transactions has some issues (user interface))
- Issue 11161 (Can't select autocomplete when using a screen reader)
- Issue 11802 (Some attachment uploads fail silently)
- Issue 12435 (The "Related piggy banks" info card assigns the native currency symbol when dealing with a foreign currency)
- Issue 12453 (Subscriptions: Return to form checkbox doesn't work)
- Issue 12455 (native_amount conversion uses now() instead of transaction date)
- Issue 12468 (Weekly subscription not accounted to be paid if there were already a payment on that month)
- Issue 12500 (Subscriptions widget show incorrect numbers.)
- Discussion 12559 (Credit Card Balance vs Available Credit) started by @SWellock
- Issue 12577 (API: /accounts endpoint never returns credit_card_type / monthly_payment_date (missing from AccountEnrichment allowlist))
- Issue 12578 (API PUT/POST /accounts stores monthly_payment_date in a format incompatible with the web UI's date input)
- Discussion 12583 (How to search for non-foreign currency transactions)
- Issue 12607 (Foreign amount can be added but not removed from transaction)
- Issue 12608 (Add a Search icon (and function) near top of collapsed menu list)
- Issue 12626 (MySQL/MariaDB SSL options not checked for empty strings)
- Issue 12639 (Test rules endpoint always returns no results unless optional accounts argument is passed)
- PR 12642 (Fix Issue 12639 (Test rules endpoint always returns no results unless optional accounts argument is passed)
- Issue 12662 (A Search for Tags returns more page groups than required)
- Issue 12687 (Changing budgeted amount in a budget deletes notes.)
- Issue 12692 (Updating accounts of a deposit recurrence via API is rejected because the validator assumes "withdrawal")
- Issue 12694 (Updating an amount in transaction doesn't make it discoverable in search using
updated_at_after:)- Issue 12710 (Last row in CSV import imported as duplicate)
- Setting an invalid language would break your account.
Unresolved security issues
- PR 12497 (ci: pin github-action-get-latest-release to a full commit SHA)
- A variety of security findings touching CSV export, installer security and many more.
- You can overwrite arbitrary preferences. This means you can also overwrite security sensitive preferences, like your email reset code. GHSA-3wcx-g7jc-h9vc
- Removed security sensitive info from the debug page.
- Removed identifying information from the login and registration pages.
- It was possible to brute force 2FA code attempts.
- URL validation could be circumvented.
- Flushing the cache would reset some timeouts.
- A stolen password against a 2FA-protected account could lead to remote code execution
- A budget limit spanning centuries was accepted, and then recalculated day by day
- Five bad logins would let anyone take the app offline
- A small search query could cost the server many seconds of CPU
- A 2.5 KB search query could exhaust the PHP memory limit
- One GET request could make the server compute tens of thousands of dates
- Account search could return every user's bank accounts (unconfirmed but measures taken)
- One search query could return every user's transactions (unconfirmed but measures taken)
- State-changing requests woyld execute before the two-factor check decides to reject them
- Any logged-in user could run shell commands on the server through a rule action
- The audit logger would your your MFA secret, which is a potential security issue
API
- You can still use the webhooks API to connect to arbitrary and weird URLs and internal IPs.
- You will still delete everybody's purged notes when you delete your own purged notes.
- The (static) cron job token is still part of the URL if you call it over the web.
- Other issues please get in touch.
- Issue 12689 (Unable to update monthly_payment_date via API)
:strip_exif()/i/2004683476.jpeg?f=imagenormal)