Release of nginx 1.25.3, njs 0.8.2, and NGINX Unit 1.31.1

The release of web browser Firefox 119 has taken place, and an update for the long-term support branch — 115.4.0 has been created. The Firefox 120 branch has entered the beta testing stage, with a release scheduled for November 21.

Key innovations in Firefox 119:

  • An updated interface for the Firefox View page has been introduced, simplifying access to previously viewed content. The Firefox View page consolidates information about active tabs, recently accessed pages, closed tabs, and tabs from other devices in one location. The new version of Firefox View now displays information about all tabs opened in any windows, and additionally adds the ability to view the browsing history sorted by date or site.
    Release of nginx 1.25.3, njs 0.8.2, and NGINX Unit 1.31.1
  • The ability to import extensions from Chrome and Chromium-based browsers has been included. In the data import dialog from other browsers ("Import Data" on the about:preferences#general page), an option to transfer extensions has appeared. A list of 72 extensions is used for transfer, matching the identifiers of equivalent extensions that exist for both Chrome and Firefox. If any extensions from the list are present during the data import from Chrome, the native Firefox version is installed instead of the Chrome version.
    Release of nginx 1.25.3, njs 0.8.2, and NGINX Unit 1.31.1
  • Support for the ECH (Encrypted Client Hello) mechanism has been enabled, which continues the development of ESNI (Encrypted Server Name Indication) and is used to encrypt information about TLS session parameters, such as the requested domain name. The key difference between ECH and ESNI is that, in ECH, rather than encrypting at the level of individual fields, the entire TLS ClientHello message is encrypted, which helps block leaks through fields that are not covered by ESNI, such as the PSK (Pre-Shared Key) field.
  • The built-in PDF viewer now supports editing capabilities such as inserting images and text notes, in addition to the previously available freehand line drawing and text comment attachments. The new PDF editing mode is activated for only a portion of users; to enable it forcibly, the setting "pdfjs.enableStampEditor" should be activated on the about:config page.
    Release of nginx 1.25.3, njs 0.8.2, and NGINX Unit 1.31.1
  • Settings related to session recovery after browser exit have been modified. Unlike previous releases, information will now be saved not only about active tabs but also about recently closed tabs between sessions, allowing you to restore accidentally closed tabs after a restart and view their list in Firefox View. By default, data on the last 25 tabs opened in the last 7 days will be saved. Data about tabs in closed windows will also be considered, and the list of closed tabs will be processed in the context of all windows, not just the current one.
  • The capabilities of Total Cookie Protection mode have been expanded, where a separate isolated cookie storage is used for each site, preventing cookies from being used to track movement between sites (all cookies set by third-party blocks loaded on the site (iframes, js, etc.) are tied to the site from which these blocks are loaded). The new version implements the isolation of the URI scheme 'blob:....' (Blob URL), which can potentially be used to transmit information suitable for tracking users.
  • For users of the strict mode of Enhanced Tracking Protection (ETP), additional protection against indirect user identification through font analysis has been enabled — visible fonts to websites are limited to system fonts and fonts from standard language packs.
  • In the Firefox snap package, support has been implemented for using the native Ubuntu file chooser dialog when accessing data from other browsers, as well as support for determining available capabilities based on the installed version of xdg-desktop-portal.
  • Support has been added for selecting a monitor for placing the browser window launched in kiosk mode. The monitor is selected using the command line parameter '--kiosk-monitor'. The browser will switch to full-screen mode immediately after launching in kiosk mode.
  • The detection of multimedia content in files processed with the MIME type 'application/octet-stream' has been discontinued. For such files, the browser will now offer to download the file instead of starting playback.
  • In preparation for the inclusion of third-party cookie blocking in Firefox, the Storage Access API implementation has been updated. This API is used to request user permissions for accessing cookie storage from iframes when third-party cookies are blocked by default. The new implementation enhances security and includes changes to avoid potential issues with website functionality.
  • Support for ARIA (Accessible Rich Internet Applications) attributes has been added for custom elements that extend the functionality of existing HTML elements, making these elements more accessible to people with disabilities. It is now possible to set and read ARIA attributes directly for DOM elements (for example, buttonElement.ariaPressed = "true") without calling the setAttribute and getAttribute methods.
  • The HTTP header Cross-Origin-Embedder-Policy, which controls the Cross-Origin isolation mode and allows defining rules for the safe use of privileged operations on the page, has been updated to support the "credentialless" parameter, which disables the sending of credential-related information, such as cookies and client certificates.
  • The CSS function attr() has been enhanced to allow specifying a second argument whose value will be used when the specified attribute is absent or has an invalid value. For example, attr(foobar, "Default value").
  • New methods Object.groupBy and Map.groupBy have been added for grouping array elements, using a string value returned by a callback function that is called for each array element as the grouping key.
  • New methods have been introduced: String.prototype.isWellFormed() to check if a string contains well-formed Unicode text (it verifies the presence of complete surrogate pairs of composite characters only) and String.prototype.toWellFormed() for cleansing and converting Unicode text into a correct form.
  • Support for the "sendOrder" property has been added to the WebTransport.createBidirectionalStream() and WebTransport.createUnidirectionalStream() methods, allowing for the specification of relative priority for the streams being sent.
  • The AuthenticatorAttestationResponse API has introduced new methods: getPublicKey(), getPublicKeyAlgorithm(), and getAuthenticatorData().
  • The Web Authentication API has added support for credProps properties, allowing for the indication of the presence of credentials after creation or registration.
  • The API PublicKeyCredential has added methods parseCreationOptionsFromJSON(), parseRequestOptionsFromJSON(), and toJSON() for converting objects into a JSON format suitable for serialization/deserialization and transmission. server.
  • The web development tools have enhanced the interface for interactive work with CSS (Inactive CSS styles), allowing the identification of CSS properties that do not affect elements, and full support for pseudo-elements like ‘::first-letter’, ‘::cue’, and ‘::placeholder’ has been included.
  • In the built-in JSON data viewer, automatic switching to view data as raw occurs if the displayed JSON data is incorrect or corrupted.
  • Support for a system setting that hides the cursor while typing has been added on the Windows platform.
  • In the Android platform version, a crash that occurred during full-screen video playback has been fixed. Support for media queries prefers-contrast and prefers-reduced-transparency has been added in the Android 14 environment.

In addition to new features and bug fixes, Firefox 119 has resolved 25 vulnerabilities. Seventeen vulnerabilities (16 grouped under CVE-2023-5730 and CVE-2023-5731) marked as critical were caused by memory handling issues such as buffer overflows and access to already freed memory areas. These problems could potentially allow for the execution of malicious code when opening specially crafted web pages. Another critical vulnerability (CVE-2023-5721) allows clickjacking to confirm or cancel certain browser dialogs or warnings.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster