Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions CHANGES.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,32 @@

## 0.6.5 (unreleased)

- Fix: SVG (skip-Thumbor) images no longer emit uid-based scale URLs that
permanently 404. Root cause was not `purge_scales` but the volatile
`ThumborScaleStorage` introduced in 0.6.x: `get_or_generate` reads a
fresh empty per-instance dict on every traversal, so *no* uid scale URL
could ever resolve — the `plone.scale` annotation is never consulted.
Fixed on both ends: skip-types now emit the original field URL with a
modification-time cache buster (both plone.namedfile code paths, the
legacy `__init__` for 7.x and `_scale_url` for >= 8.0.0a2), the HiDPI
`srcset` attribute and the `srcset()` method emit Thumbor URLs, and
`get_or_generate` heals legacy uid URLs (cached HTML, stale
`image_scales` catalog metadata) by parsing the deterministic
`{fieldname}-{width}-{md5}` uid and regenerating the info on the fly —
restricted to widths registered in `plone.allowed_sizes`. Review
hardening on top: srcset() mirrors the parent's edge-case guards
(zero-size original, original-size back-fill, unresolvable src scale),
and the HiDPI srcset path threads crop info through for scale infos
that carry a scale name.
Closes [#17](https://github.com/bluedynamics/plone-pgthumbor/issues/17).

- Add `cdk8s-plone` to the ecosystem navigation dropdown in the docs.

- Chore: apply ruff 0.16 markdown code-fence formatting to four docs files
(pre-existing drift; the QA workflow runs the latest ruff via uvx over
the whole repo). Mark up `zope2.Public` as inline code in a security-doc
heading so vale's Microsoft.Spacing rule no longer trips on it.

## 0.6.4 (2026-04-20)

- Fix: `_needs_auth_url()` no longer issues a PostgreSQL query per image.
Expand Down
4 changes: 2 additions & 2 deletions docs/sources/explanation/security.md
Original file line number Diff line number Diff line change
Expand Up @@ -140,7 +140,7 @@ method:
The auth handler is registered via Thumbor's `HANDLER_LISTS` configuration:

```python
HANDLER_LISTS = ['zodb_pgjsonb_thumborblobloader.auth_handler']
HANDLER_LISTS = ["zodb_pgjsonb_thumborblobloader.auth_handler"]
```

`get_handlers()` returns a list of `(url_regex, handler_class, context)` tuples
Expand Down Expand Up @@ -206,7 +206,7 @@ Invalid or
| Object not in catalog | 404 | Unknown object |
| Database error | 503 | Service unavailable |

### Why zope2.Public permission
### Why `zope2.Public` permission

The `@thumbor-auth` service is registered with `permission="zope2.Public"` -- it
is accessible without authentication.
Expand Down
6 changes: 5 additions & 1 deletion docs/sources/how-to/configure-thumbor.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,6 @@ HANDLER_LISTS = [
"thumbor.handler_lists.healthcheck",
"zodb_pgjsonb_thumborblobloader.auth_handler",
]

```

The healthcheck handler must come first so `/healthcheck` is matched before
Expand Down Expand Up @@ -80,6 +79,7 @@ Can also be set via the `THUMBOR_SECURITY_KEY` environment variable:

```python
import os

SECURITY_KEY = os.environ.get("THUMBOR_SECURITY_KEY", "")
```

Expand Down Expand Up @@ -137,6 +137,7 @@ Both settings can be configured via environment variables:

```python
import os

AUTO_WEBP = os.environ.get("THUMBOR_AUTO_WEBP", "true").lower() in ("true", "1", "yes")
AUTO_AVIF = os.environ.get("THUMBOR_AUTO_AVIF", "false").lower() in ("true", "1", "yes")
```
Expand Down Expand Up @@ -179,6 +180,7 @@ Can be configured via environment variable:

```python
import os

_detectors = os.environ.get("THUMBOR_DETECTORS", "")
if _detectors:
DETECTORS = [d.strip() for d in _detectors.split(",") if d.strip()]
Expand Down Expand Up @@ -227,6 +229,7 @@ Can be set via environment variable:

```python
import os

PGTHUMBOR_DSN = os.environ.get("PGTHUMBOR_DSN", "")
```

Expand Down Expand Up @@ -271,6 +274,7 @@ Can be set via environment variable:

```python
import os

PGTHUMBOR_PLONE_AUTH_URL = os.environ.get("PGTHUMBOR_PLONE_AUTH_URL", "")
```

Expand Down
1 change: 0 additions & 1 deletion docs/sources/how-to/write-crop-provider.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,6 @@ from zope.interface import implementer

@implementer(ICropProvider)
class MyCropProvider:

def __init__(self, context):
self.context = context

Expand Down
Loading
Loading