Software-update: Firefly III 6.7.1

Firefly III logo (Über) Firefly III is een in PHP geschreven webapplicatie waarmee een overzicht van je financiën kan worden bijgehouden. Het kan de data importeren vanuit csv-bestanden, de GoCardless-api of de Spectre-api. Voor meer informatie over dit programma verwijzen we naar deze pagina. De ontwikkelaar loopt ook op Tweakers rond en bespreekt zijn applicatie in het grote 'Firefly III'-topic. Versie 6.7.1 is uitgekomen en hier zijn de volgende veranderingen en verbeteringen in aangebracht:

Known issues
  • Editing and creating split transactions may sometimes mix up the order of the splits. The data itself is never mixed up however.
  • Some user managed to get a PR co-authored by Claude past my eagle eyes. Sorry about that. Luckily just a small fix.
  • Many small and large usability issues still exist in the new layout. My humble apologies. I could not catch them all (sad Pikachu face).
Added
  • Added a view for all transactions.
Changed
  • oAuth tokens are now on a separate page.
  • The rule engine features an "expression engine". It is now disabled by default and must be turned on again in /settings.
  • Switched from Twig template engine to Blade.
  • Introduced a new version of the AdminLTE template.
  • Introduces new forms for creating and editing transactions
  • Switched from Font Awesome to Bootstrap Icons
  • Login page now no longer advertises it's Firefly III
  • Cron jobs are now per user, only users with the "owner" role can force the cron job or run it for different users.
Removed
  • Old forms, old code, old images.
Fixed
  • Issue 10652 (Handling split transactions has some issues (user interface))
  • Issue 11161 (Can't select autocomplete when using a screen reader)
  • Issue 11802 (Some attachment uploads fail silently)
  • Issue 12435 (The "Related piggy banks" info card assigns the native currency symbol when dealing with a foreign currency)
  • Issue 12453 (Subscriptions: Return to form checkbox doesn't work)
  • Issue 12455 (native_amount conversion uses now() instead of transaction date)
  • Issue 12468 (Weekly subscription not accounted to be paid if there were already a payment on that month)
  • Issue 12500 (Subscriptions widget show incorrect numbers.)
  • Discussion 12559 (Credit Card Balance vs Available Credit) started by @SWellock
  • Issue 12577 (API: /accounts endpoint never returns credit_card_type / monthly_payment_date (missing from AccountEnrichment allowlist))
  • Issue 12578 (API PUT/POST /accounts stores monthly_payment_date in a format incompatible with the web UI's date input)
  • Discussion 12583 (How to search for non-foreign currency transactions)
  • Issue 12607 (Foreign amount can be added but not removed from transaction)
  • Issue 12608 (Add a Search icon (and function) near top of collapsed menu list)
  • Issue 12626 (MySQL/MariaDB SSL options not checked for empty strings)
  • Issue 12639 (Test rules endpoint always returns no results unless optional accounts argument is passed)
  • PR 12642 (Fix Issue 12639 (Test rules endpoint always returns no results unless optional accounts argument is passed)
  • Issue 12662 (A Search for Tags returns more page groups than required)
  • Issue 12687 (Changing budgeted amount in a budget deletes notes.)
  • Issue 12692 (Updating accounts of a deposit recurrence via API is rejected because the validator assumes "withdrawal")
  • Issue 12694 (Updating an amount in transaction doesn't make it discoverable in search using updated_at_after:)
  • Issue 12710 (Last row in CSV import imported as duplicate)
  • Setting an invalid language would break your account.
Security
  • PR 12497 (ci: pin github-action-get-latest-release to a full commit SHA)
  • A variety of security findings touching CSV export, installer security and many more.
  • You can overwrite arbitrary preferences. This means you can also overwrite security sensitive preferences, like your email reset code. GHSA-3wcx-g7jc-h9vc
  • Removed security sensitive info from the debug page.
  • Removed identifying information from the login and registration pages.
  • It was possible to brute force 2FA code attempts.
  • URL validation could be circumvented.
  • Flushing the cache would reset some timeouts.
  • A stolen password against a 2FA-protected account could lead to remote code execution
  • A budget limit spanning centuries was accepted, and then recalculated day by day
  • Five bad logins would let anyone take the app offline
  • A small search query could cost the server many seconds of CPU
  • A 2.5 KB search query could exhaust the PHP memory limit
  • One GET request could make the server compute tens of thousands of dates
  • Account search could return every user's bank accounts (unconfirmed but measures taken)
  • One search query could return every user's transactions (unconfirmed but measures taken)
  • State-changing requests woyld execute before the two-factor check decides to reject them
  • Any logged-in user could run shell commands on the server through a rule action
  • The audit logger would your your MFA secret, which is a potential security issue
Unresolved security issues
  • You can still use the webhooks API to connect to arbitrary and weird URLs and internal IPs.
  • You will still delete everybody's purged notes when you delete your own purged notes.
  • The (static) cron job token is still part of the URL if you call it over the web.
  • Other issues please get in touch.
API
  • Issue 12689 (Unable to update monthly_payment_date via API)

Firefly III screenshot

Versienummer 6.7.1
Releasestatus Final
Website Firefly III
Download https://github.com/firefly-iii/firefly-iii/releases/tag/v6.7.1
Licentietype GPL

Door Bart van Klaveren

Downloads en Best Buy Guide

15-09-2026 • 07:30

0

Bron: Firefly III

Reacties

Sorteer op:

Weergave:

Er zijn nog geen reacties geplaatst


Om te kunnen reageren moet je ingelogd zijn