Date Period
October 05, 2026
September 25, 2026
GET /asset/api/v2/assets listing endpoint now requires an instance API key. External integrators must send their instance API key on this endpoint or the request will be rejected.September 25, 2026
insites_core's shared admin layout and external CRM activity scripts from EOL 0.x releases to 1.19.0insites_core's dependency partialsupload_restrictions schema and a shared validate_upload function, so file-upload limits are declared once and enforced consistentlycrossorigin to the moment.js tag on the Event Stream viewid alongside uuid and its reference label, on every methodYYYY-MM-DDGET /insites/core/administrators/:uuid now returns 404 for an unknown or malformed uuid instead of 200 with an empty result setadd_event leaking into the response body on 36 unwrapped v2 external API endpoints, and guard it so a blank Event Stream response cannot throw ParseJsonTagErroris_archived: false explicitly on every Contact create path, so new contacts cannot be created in an indeterminate archived stateSeptember 18, 2026
September 16, 2026
Error responses keep the page's content type: A page that sets its content type, from its format or via {% response_headers %}, no longer has an error rendered afterwards re-negotiated against the Accept header. Unrecognised formats render as text/plain, and errors on .js pages return a JSON string literal so the browser never parses an error message as script.
Clear response when an instance has no object storage: Requesting a presigned upload URL used to return nothing, and sync reported a failed fetch. The endpoint now returns 501 with a direct_upload_unavailable error, and the CLI falls back to uploading assets through the instance.
Host-relative asset URLs with local storage: When an instance serves its own assets from disk, asset_url now returns a host-relative URL instead of pointing at a CDN that never received the files, or raising when no asset host is set. Instances using a CDN are unaffected.
Dynamically cached pages without a layout: A page combining dynamic_cache with layout: "" rendered on the first request and then failed on every cache hit. Pages that declare no layout are now served from cache as-is, which fixes cached sitemap.xml pages.
Redundant Liquid context on cache hits: The layout no longer builds a second Liquid context and reparses the layout value on every dynamic cache hit.
Partner Portal URLs on non-default ports: An instance registered against a portal on a non-default port dropped the port, so later token validations went to the default port and surfaced as a plain 401. Local setups and private stacks were affected; production was not.
Swapped exception names in low-level error logs: IP spoofing attempts were logged as missing-parameter errors and vice versa. The 403 and 406 statuses returned were already correct.
September 15, 2026
September 09, 2026
Stricter YAML parsing: The YAML parser now rejects unsafe input instead of silently rewriting it, so three patterns that used to deploy will now fail. A file carrying one of them has been deploying a value other than the one it reads, so this is worth checking before you upgrade.
:draft — a leading colon. Remove the colon.!ruby/object:Foo — delete the tag declaration.*missing — an orphaned alias. Make sure a matching anchor exists.Standard YAML features are unaffected: anchors, aliases, merges and dates all continue to work.
Content-Type: application/json whose body is malformed now receives a structured JSON error, {"status":400,"error":"There was a problem in the JSON you submitted: ..."}, instead of plain text. Other content types still receive a text response, now with an explicit Content-Type: text/plain header.August 27, 2026
/insites/api/v2/endpoints, gated by the instance API key. Every endpoint must carry at least one authorization policy (no public-by-omission), the slug and file path are namespace-validated, inputs are allow-listed, and each change is recorded in the event stream. Documented under the new API section in the API docs.{% function %}, and when to use a controller instead of the HTTP API. Includes explicit guidance for AI assistants so generated on-instance Liquid uses controllers rather than HTTP calls.{API_KEY} placeholder consistently across every endpoint and module..md to a documentation URL now redirects to the real Markdown version instead of returning HTML with a markdown content type. Fixed the CMS, Forms, Permissions, and Stripe reference sections rendering another module's content.params: params named argument, so the example is copy-paste-valid.& in cURL example URLs and example data, instead of an HTML-escaped &.company.name) is documented as returning an error.August 26, 2026
Z.August 26, 2026
\\ represents one literal backslash. '\' and "\"" no longer work — use the doubled forms instead.escape_regex filter: Escapes every character that carries a special meaning in a regular expression, so the result matches the input literally. Use it alongside replace_regex, matches or regex_matches.Deploy errors report a line number: Syntax errors and unknown tags now read like Liquid syntax error (line 4): Unknown filters: not_a_filter, instead of leaving you to find the spot.
Deprecated filter aliases published: The filter reference now lists aliases as deprecated entries in their own right, including compact, select, reject, detect, any, sort_by, group_by, flatten, dig and fetch. Every one of them keeps working.
Argument types published: Filter and tag arguments now publish their declared type, whether they are required, and the calling convention.
Ruby 4: The platform now runs on Ruby 4.0.
Asset phase in deploy reports: A deploy report carries an asset_status field reading in_progress, success or error.
parse_json: {% assign %} takes a JSON literal directly.{% return %} and {% redirect_to %} work inside {% for %} and {% tablerow %} loops.
A %} written inside a comment no longer truncates a {% liquid %} tag.
Assets whose names contain spaces or escaped characters load correctly.
Uniqueness locks left by a failed job are released, and lock lifetime is capped at one hour.
A malformed request body returns 400, and an unparseable transfer coding returns 501.
Filter by
Date Period