---
title: "v1.7.2"
description: "The Payload family moves to 3.90.0, a Payload security release, and the bundled Lexical admin patch is retargeted to it."
requested_language: hu
language: en
translation_notice: "This page isn't translated yet"
url: https://docs.systhema.app/hu/changelog/v1.7.2
version: changelog
docs_index: https://docs.systhema.app/hu/llms.txt
---
> This page isn't translated yet. Showing English.


## ✨ Highlights

1.7.2 moves the Payload family to **3.90.0**, a Payload security release, and retargets the bundled Lexical admin patch to it. Nothing else changes. Payload's own notes say "contains a set of critical security fixes, upgrade as soon as possible", so this ships on its own rather than waiting for the next feature release.

---

## ⬆️ Upgrade

```bash
pnpm add -g @systhemaui/cli@latest
cd <your-project>
systhema upgrade --dry-run
systhema upgrade --yes --allow-database
```

The upgrade bumps `@systhemaui/*` and moves `payload` and every `@payloadcms/*` package to 3.90.0. A project that pins the family exactly, as the 1.7.1 scaffold does, is moved to the exact new version. The bundled Lexical patch is swapped for the 3.90.0 build in the dependencies phase, before the install, so no dangling patch key can abort it.

**Then, on a relational database, add the column Payload 3.90.0 introduces.** Every auth collection gains `resetPasswordRequestedAt`. With a migration directory:

```bash
pnpm payload migrate:create add-reset-password-requested-at
pnpm payload migrate
```

On a push-mode PostgreSQL deployment, `systhema migrate --schema` adds it, since the change is purely additive. Types regenerate as part of the upgrade.

**Pending scheduled publishes need re-creating.** 3.90.0 preserves the scheduling user's auth collection on queued publish and unpublish events, and events queued before the upgrade do not carry it.

**If you wrote your own client upload handler, it needs three changes.** Projects using the stock `@payloadcms/storage-*` handlers need nothing — this is only for a hand-written `createClientUploadHandler`.

- **Direct uploads are signed.** The server handler now returns a `headers` object beside the signed `url`, and the browser's `PUT` must send it verbatim — it includes `If-None-Match: '*'`, which is part of the signature, so omitting it fails the upload. The request that asks for the URL must also pass `docPrefix` along with `collectionSlug`, `filename`, `filesize` and `mimeType`.
- **The document create must carry the receipt.** The handler's return value has to include the server-issued `clientUploadContext.signedReceipt` (plus its `prefix`); a collection with `requiresClientUploadReceipt` rejects the create without it.
- **Client-uploaded objects live one level deeper.** The storage key is now `{prefix}/{_objectKey}/{filename}`, so any server-side code that rebuilds a key as `{prefix}/{filename}` must read the document's `_objectKey` and join it in.

Payload's full notes: [payloadcms/payload v3.90.0](https://github.com/payloadcms/payload/releases/tag/v3.90.0).

---

## ⚠️ Breaking & Behavioral Changes

Every entry here is Payload's, not Systhema's. They are listed because the scaffold now installs 3.90.0 and a Systhema project inherits them. Payload's full notes are at [payloadcms/payload v3.90.0](https://github.com/payloadcms/payload/releases/tag/v3.90.0).

### 1. Stricter SVG and XML upload validation

SVG, XHTML and XML-family uploads are validated more strictly, direct client uploads must send the required metadata, and path components are no longer retained in new filenames. A project that needs the previous behaviour sets `allowRestrictedFileTypes: true` on the upload collection.

### 2. Multipart uploads are capped at 50 MB by default

Raise `upload.requestSizeLimit` in the Payload config if a project relies on larger multipart requests.

### 3. API keys are no longer readable after generation

`auth.useAPIKey: true` now hides the key after it is created. `useAPIKey: { reveal: true }` restores the old behaviour. Systhema's own Users collection does not use API keys.

### 4. Password changes revoke other sessions, and forgot-password is throttled

No action needed beyond the column migration above.

### 5. External file fetches require a trusted origin

A project with `upload.disableLocalStorage: true` that relies on Payload fetching relative URLs needing a session cookie must configure `serverURL` or add its origin to CORS or CSRF. Non-HTTP(S) external file URLs are no longer accepted.

### 6. Form Builder submission read access defaults to the admin collection

Systhema already sets `formSubmissionOverrides.access` explicitly, and Payload's notes say an existing override continues to be respected, so a Systhema project sees no change here.

---

## 🐛 Fixes & Internal Improvements

- **The bundled Lexical patch targets 3.90.0.** The 3.89.0 diff already applied to the new version apart from a trailing newline upstream dropped from `initLexicalFeatures.js`, which is enough for `git apply` to refuse it and is exactly the check the upgrade pre-flight runs. The patch is regenerated rather than re-keyed, so it applies byte-for-byte, and `systhema doctor` on a project still resolving 3.89.0 reports the mismatch (#218)

---

## List of all changes

Every commit between `v1.7.1` and `v1.7.2`.

### 🧹 Chores

#### payload,cli,templates/payload,apps/demo

- chore(payload,cli,templates/payload,apps/demo): move the Payload family to 3.90.0 (#218)
