- Restrict page revision history to editors and exclude deleted pages, so the contents of a deleted page are no longer readable through its history.
- Authorize uploads against current access to the book, so someone whose access has been revoked can no longer add files to it.
- Require access to the book before serving attachments of unpublished books, and stop marking them as publicly cacheable.
Writebook Changelog
1.2.2
1.2.1
- Disable libvips unfuzzed operations to harden image processing.
- Upgrade loofah to 2.25.2 and rails-html-sanitizer to 1.7.1.
- Update dependencies: puma 7.2.1, sqlite3 2.9.5, nokogiri 1.19.4, crass 1.0.7, net-imap, erb, concurrent-ruby, and more.
- Add a release script.
1.2.0
Security
- Delete server-side session on logout.
- Sanitize markdown output in edit history and TOC edit views.
- Sanitize search results to prevent XSS from FTS5 output.
Security-related dependency updates: rack, rack-session, uri, rails-html-sanitizer, nokogiri, addressable.
Features
- Markdown rendering for books and leaves — appending
.mdto any book or leaf URL renders it as inline markdown. - YAML frontmatter in markdown views — markdown output includes title, author, and URL metadata.
- HTML link tags for markdown alternate format — pages include
<link>tags pointing to the markdown version. - Use relative links for uploaded files — uploaded file URLs are now relative, improving portability.
Other
- Add README and license.
- Add publish-image workflow for container releases.
- Remove redundant dev credentials and old deployment configs.
- Update fixtures to use example domain.
1.1.0
- Toggle table of contents in new sidebar.
- Allow searching inside books.
- Fix that clicking new page buttons would sometimes trigger unexpected navigation.
- Update dependencies.
1.0.6
Fix issue with forwarded headers when running behind an external proxy.
1.0.5
- Fix incorrect configuration when running without TLS (via Thruster update).
- Fix a typo in The Writebook Manual.
1.0.4
- Update to latest Thruster version.
- Allow navigating between pages with a swipe gesture on touch devices.
- Fix incorrect icon on first run form.
1.0.3
- Ensure signed QR code links are URL safe.
- Ensure text is visible on white theme cover.
- Improve images used in OpenGraph metadata.
- Minor layout adjustments for mobile.
- Edits and improvements to The Writebook Manual.
- Allow
summaryandsourcetags in Markdown.
1.0.2
- Fix broken link in
og:url. - Refactor user profile links to simplify controller permissions.
- Use signed links for QR code generation to prevent tampering.
1.0.1
Fix bug that prevented non-admin users from updating their profile.
1.0.0
Writebook goes live.
ONCE™ products are designed, built, and backed by
37signals™. Copyright © 37signals LLC. All rights reserved.
Anyone buying, using, or receiving a
ONCE™ product is subject to our software license agreement.
- Writebook
- 100% Free
What’s included?
- Easy installation
- Free updates
- It’s open source (you get the code)
Review all of the FAQs prior to installation.