Releases
v3.0.7
Web Packages
Utopia now uses web-packages v0.2 after the project was renamed from bake-node. Applications should use the web-packages key in package.json and invoke package management through the web:packages Bake namespace. The generated .manifest.json format remains compatible.
v3.0.6
JavaScript Packages
Utopia now depends on bake-node for JavaScript dependency installation and static package projection. Utopia::Components and utopia:components:update have been removed. Replace the old task with bundle exec bake node:packages:static, and migrate package selection from utopia.components to bake-node.packages in package.json.
Use Utopia::ImportMap.load_manifest("public/_components") to load the generated browser import mappings directly from the Bake Node manifest.
v3.0.5
- Breaking Remove support for JavaScript packages installed in
lib/components; usenode_modulesinstead. - Breaking Expose
attr :linksas the content link resolver rather than an indexed lookup method. - Security Authenticate encrypted session cookies using AES-256-GCM. Existing session cookies are invalidated.
- Constrain content node local paths to the configured content root.
- Security Redact sensitive exception report fields and make bounded request body attachments opt-in.
- Return
416 Range Not Satisfiablefor unsatisfiable static file byte ranges.
v3.0.0
The 3.0.x series is considered a development release while the protocol HTTP application and controller interfaces stabilize.
- Breaking Require Ruby 3.3 or later.
- Breaking Replace the Rack-centric application boundary with
class Utopia::ApplicationandProtocol::HTTP::Middleware. Applications now useconfig/application.rbandconfig/serve.rbinstead ofconfig.ru. - Breaking Separate complete protocol responses from semantic controller results. Use
respond!with aProtocol::HTTP::Response, orsucceed!with a value serialized bymodule Utopia::Controller::Respond. - Parse request bodies at the controller layer using
protocol-content, independently of URL query parameters. - Resolve localization through immutable request preferences, avoiding repeated internal controller requests.
- Split redirection handling into focused middleware for rewrites, moved resources, directory indexes, and error documents.
- Security Fix handling of redirects that start with
//to prevent open redirect vulnerabilities. - Normalize request URLs using
Protocol::URLand use structured paths throughout the middleware stack. - Resolve static files through encoded URL paths, with improved
HEAD, range, and validator handling. - Use
protocol-mediaandprotocol-httpfor response and language negotiation, removing thehttp-acceptdependency.
v2.31.0
- Add agent context.
- Better simplification of relative paths, e.g.
../../foois not modified tofoo. - Move top level classes into
class Middlewarein their respective namespaces. - Move
Utopia::ResponderintoUtopia::Controllerlayer.
v2.30.1
- Minor compatibility fixes.
v2.27.0
- Improved error logging using
Consolegem. - Only install
npm ls --productiondependencies intopublic/_components.