Docs

This page isn't translated yet

v1.7.2

The Payload family moves to 3.90.0, a Payload security release, and the bundled Lexical admin patch is retargeted to it.

On this page

✨ HighlightsLink to this section

1.7.2 moves the Payload family to 3.90.0, a Payload security release, and retargets the bundled Lexical admin patch to it. Nothing else changes. Payload's own notes say "contains a set of critical security fixes, upgrade as soon as possible", so this ships on its own rather than waiting for the next feature release.


⬆️ UpgradeLink to this section

pnpm add -g @systhemaui/cli@latest
cd <your-project>
systhema upgrade --dry-run
systhema upgrade --yes --allow-database

The upgrade bumps @systhemaui/* and moves payload and every @payloadcms/* package to 3.90.0. A project that pins the family exactly, as the 1.7.1 scaffold does, is moved to the exact new version. The bundled Lexical patch is swapped for the 3.90.0 build in the dependencies phase, before the install, so no dangling patch key can abort it.

Then, on a relational database, add the column Payload 3.90.0 introduces. Every auth collection gains resetPasswordRequestedAt. With a migration directory:

pnpm payload migrate:create add-reset-password-requested-at
pnpm payload migrate

On a push-mode PostgreSQL deployment, systhema migrate --schema adds it, since the change is purely additive. Types regenerate as part of the upgrade.

Pending scheduled publishes need re-creating. 3.90.0 preserves the scheduling user's auth collection on queued publish and unpublish events, and events queued before the upgrade do not carry it.

If you wrote your own client upload handler, it needs three changes. Projects using the stock @payloadcms/storage-* handlers need nothing — this is only for a hand-written createClientUploadHandler.

  • Direct uploads are signed. The server handler now returns a headers object beside the signed url, and the browser's PUT must send it verbatim — it includes If-None-Match: '*', which is part of the signature, so omitting it fails the upload. The request that asks for the URL must also pass docPrefix along with collectionSlug, filename, filesize and mimeType.
  • The document create must carry the receipt. The handler's return value has to include the server-issued clientUploadContext.signedReceipt (plus its prefix); a collection with requiresClientUploadReceipt rejects the create without it.
  • Client-uploaded objects live one level deeper. The storage key is now {prefix}/{_objectKey}/{filename}, so any server-side code that rebuilds a key as {prefix}/{filename} must read the document's _objectKey and join it in.

Payload's full notes: payloadcms/payload v3.90.0 (opens in new tab).


⚠️ Breaking & Behavioral ChangesLink to this section

Every entry here is Payload's, not Systhema's. They are listed because the scaffold now installs 3.90.0 and a Systhema project inherits them. Payload's full notes are at payloadcms/payload v3.90.0 (opens in new tab).

1. Stricter SVG and XML upload validationLink to this section

SVG, XHTML and XML-family uploads are validated more strictly, direct client uploads must send the required metadata, and path components are no longer retained in new filenames. A project that needs the previous behaviour sets allowRestrictedFileTypes: true on the upload collection.

2. Multipart uploads are capped at 50 MB by defaultLink to this section

Raise upload.requestSizeLimit in the Payload config if a project relies on larger multipart requests.

3. API keys are no longer readable after generationLink to this section

auth.useAPIKey: true now hides the key after it is created. useAPIKey: { reveal: true } restores the old behaviour. Systhema's own Users collection does not use API keys.

4. Password changes revoke other sessions, and forgot-password is throttledLink to this section

No action needed beyond the column migration above.

5. External file fetches require a trusted originLink to this section

A project with upload.disableLocalStorage: true that relies on Payload fetching relative URLs needing a session cookie must configure serverURL or add its origin to CORS or CSRF. Non-HTTP(S) external file URLs are no longer accepted.

6. Form Builder submission read access defaults to the admin collectionLink to this section

Systhema already sets formSubmissionOverrides.access explicitly, and Payload's notes say an existing override continues to be respected, so a Systhema project sees no change here.


🐛 Fixes & Internal ImprovementsLink to this section

  • The bundled Lexical patch targets 3.90.0. The 3.89.0 diff already applied to the new version apart from a trailing newline upstream dropped from initLexicalFeatures.js, which is enough for git apply to refuse it and is exactly the check the upgrade pre-flight runs. The patch is regenerated rather than re-keyed, so it applies byte-for-byte, and systhema doctor on a project still resolving 3.89.0 reports the mismatch (#218)

List of all changesLink to this section

Every commit between v1.7.1 and v1.7.2.

🧹 ChoresLink to this section

payload,cli,templates/payload,apps/demoLink to this section

  • chore(payload,cli,templates/payload,apps/demo): move the Payload family to 3.90.0 (#218)