projectdoc Toolbox 4.13.3 Release Notes

Bugfix release with one security fix.

Today we released version 4.13.3 of the projectdoc Toolbox.

This is release provides a collection of bug fixes, including one security fix.

The projectdoc Toolbox is an add-on for Confluence supporting agile software development teams to collaborate on process, project, system, and product documentation. 

New and Noteworthy

Security Issues

The External Quote Macro fails to encode parameter values provided by a user with page edit privileges.

Installation Instructions

Install the new OBR of the projectdoc Toolbox.

List of Changes

The following changes are part of the latest projectdoc Toolbox for Confluence

Key Summary T P Description
PDAC-1504 Encoding Issues with Quote External Macro Bug Critical (migrated)

Parameters are not fully encoded when the Quote External Macro is rendered.

This is an security issue if the attacker has write privileges on pages.

PDAC-1505 Render Error on Invalid Protocol for Quote External Macro Improvement Minor (migrated)

In case an URL with an invalid protocol is used by the External Quote macro then this URL is silently ignored and no link is rendered. Instead an error box should be rendered by the macro to signal clearly that the protocol is wrong.

PDAC-1499 Render specific Error Message on missing Document Improvement Minor (migrated)

In case the documents of the Code Macro is not specified, then a specific error message should be rendered.

PDAC-1506 Tour by Property Macro fails on empty Name List in Debug Mode Bug Minor (migrated)

If debug mode is activate then the Tour-by-Property Macro reports text from the Name List Macros as missing items. Instead it should simple render no hits.

PDAC-1503 Render Macro Error Message in Error Box Bug Minor (migrated)

The message is currently styled as information on Confluence 7.x.

PDAC-1502 Render Protocol Error not to Log Bug Minor (migrated)

The Link External Macro logs invalid protocols to the server's error log. It should only be displayed in the user's UI.

PDAC-1501 Fix I18N for Code Macro Bug Minor (migrated)

Macro fails to access resource bundle with the correct keys. The keys used are provided by the InfoSys extension. If this extension is not deployed, the resources are missing.

The keys must be altered to point to resources in the Toolbox's bundle.

PDAC-1498 Fix Encoding of Code Macro Content Bug Minor (migrated)

The code content of the Code Macro must not be encoded.

Resources

Release Notes for the projectdoc Toolbox
Relevant information on changes to the projectdoc Toolbox for Confluence introduces by new versions of this app.
Glossary
Terms used in and defined for projectdoc.
FAQs
Questions and answers related to the projectdoc Toolbox and Confluence.