Changelog History
Page 1
-
v1.1.0.1 Changes
April 17, 2026๐ง I am currently trying to decide on the maintenance mode of spacecookie going forward, especially the included server daemon. It would help me to hear from users of this software, in particular what parts of it they're using. If you count yourself among those users, I'd be grateful if you'd reach out to me at sternenseemann@systemli.org or via the issue tracker.
- Fix menu responses not being terminated by the Lastline pattern.
- โ Add
install-daemonCabal flag (on by default) which controls whether the executable component of the package is built.
-
v1.1.0.0 Changes
April 07, 2026API BREAKING CHANGE : Remove
Network.Gopher.Util.
Previous users of these utilities are encouraged to copy the utilities
from 1.0.0.3 into their own code and adapt them to their needs.โ Migrate from
filepath-bytestringtofilepath >= 1.5.2and
โos-string >= 2.0.6. These changes have been tested with GHC 9.10.3,
GHC 9.12.3 and 9.14.1.๐ Fix crash on malformed port values when parsing a gophermap using
Network.Gopher.Util.Gophermap.๐ Fix crashes if encoding assumptions are violated in
GopherLogStr
when converting toStringor theTexttypes.
-
v1.0.0.3 Changes
May 03, 2025Security fix :
ResolvesanitizePathnot eliminating..from paths. This affects users
ofsanitizePathandsanitizePathIfNotUrlfromNetwork.Gopher.Util.This issue only affects the spacecookie library, not the spacecookie server
daemon since a separate check would prevent it from handling such malicious
requests (which delayed the discovery of this bug). It is probably wise to
โฌ๏ธ upgrade either way.๐ Note that gophermap parsing behavior is unchanged, i.e. it just
normalises
paths, even thoughmakeGophermapFilePathused to callsanitizePathin
previous versions. This is due to the assumption that gophermaps come from a
๐ trusted source and/or paths produced from gophermap parsing aren't used to
access files directly, i.e. those paths are only served to clients (whose later
requests are subject to selector sanitization) as selectors in menus. If those
assumptions don't hold for your code, you will need to further sanitize the
paths returned fromgophermapToDirectoryResponse. -
v1.0.0.2 Changes
October 03, 2022 -
v1.0.0.1 Changes
November 29, 2021๐ This release fixes compilation with
aeson >= 2.0. -
v1.0.0.0 Changes
March 16, 2021๐ Read the full CHANGELOG.
TL;DR:
- ๐ง Server daemon: Configurable logging, full compatibility with Bucktooth gophermaps, fix networking bug related to curl, DoS migitations, โฆ
- โ
Library: Rework request representation, use more efficient and flexible
ByteStringoverString, user-implementable logging, โฆ
-
v0.2.1.2 Changes
May 13, 2020๐ Fix build by adjusting dependency constraints.
-
v0.2.1.1 Changes
December 10, 2019- Server
- Make
userparameter in config optional. If it is not given or set tonull,spacecookiewon't attempt to change its UID and GID. This is especially useful, if socket activation is used. In that case it is not necessary to start spacecookie asrootsince systemd sets up the socket, sospacecookiecan be already started by the right user and doesn't need to change UID. - Example Systemd config files
SocketModeis now660instead of default666.- Set
UserandGroupforspacecookie.serviceas well. - Set
"user": nullinspacecookie.json
- Make
- Library
- Fixed issue that led to
runGopher*trying to change UID even if it wasn't possible (not running as root). This especially affected thespacecookieserver, sincecRunUserNamewould always beJust. - Made logging related to
dropPrivilegesclearer.
- Fixed issue that led to
- Server
-
v0.2.1.0 Changes
October 20, 2019- ๐ Improved systemd support.
- Support for the notify service type
- Support for socket activation and socket (fd) storage
- To make use of these new features you'll have to update your service files
- โ Added
defaultConfigvalue to prevent future breakage in software using the
library when theGopherConfigtype is extended. - ๐จ Pretty print IPv6 addresses in logging
- ๐ Improved systemd support.
-
v0.2.0.1 Changes
May 23, 2019โ Added version constraints for
baseto please hackage.