HumHub
Open-source private social network and collaboration platform
Alternative to: Facebook Workplace, Yammer, Nextdoor
About
Versions (104)
v1.19.0-beta.2
2026-08-19- Fix #8350: A configured but unreachable database presented the web installer — offering to re-setup an already installed instance during a transient outage — instead of an error; such requests now return a 503
- Fix #8393: #8350 returned a 503 for any database error, so a fresh or incompletely configured install (server reachable but the database missing, credentials wrong, or the DSN lacking a database name) was blocked instead of shown the installer; a 503 is now returned only when the database server itself is unreachable
- Enh #8390: Removed the redundant My Spaces dropdown click handler — the lazy space list is already loaded on open, and the case where the dropdown was opened before its widget initialized is covered by the init-time check from #8384
- Enh #8389: Removed the unused
$rightparameter fromBootstrapVariationsTrait::icon()(Button/Badge/Link/Alert) and fromMenuLink::setIcon()—$optionsis now the second parameter oficon()instead of the third, seedocs/develop/module-migrate.md - Enh #8389: Buttons styling by using flex and gap instead of a right margin on the icon
- Fix #8380: Activities of private spaces leaked into the activity summary mail and dashboard activity box of users with a pending space invite or join request
- Fix #8366: Duplicate key error when concurrent requests stored the same setting, e.g. theme variables after a theme switch
- Enh #8363: A download served by a redirect to a temporary storage URL (a mount whose
useTemporaryUrls()returns true, e.g. the S3 module) arrived in the browser namedfileand without a usable content type — uploads are stored under an object key ending infileand the redirect target carries noContent-Disposition, so the browser derived both from the URL path;DownloadActionnow passes the file name and mime type totemporaryUrl()via the new storage-neutralMountConfigInterface::CONFIG_CONTENT_DISPOSITIONandCONFIG_CONTENT_TYPEconfig keys, which backends able to override response headers on a temporary URL (S3’sresponse-content-disposition) honor and others ignore. AddedFileHelper::getContentDispositionHeaderValue()for the header value, sinceResponse::getDispositionHeaderValue()builds the same thing but is protected - Fix #8352: A
themes/HumHubdirectory left behind in the webroot by the 1.19 move of the core theme intoprotected/humhub/themes(#8102) shadowed the real core theme whenever a theme was resolved by name —ThemeHelper::getThemes()keys themes by name and merged the webroot themes over the core ones, so the SCSS build looked forthemes/HumHub/scss/variables.scssand the CSS could not be compiled; core themes now win on a name collision. This also affected the theme parent lookup, so a child theme inthemes/or in<module>/themes/inherited from the stale directory. Unlike #8335 this also covers a leftover directory that still contains itsscss/variables.scssand therefore loads as a valid theme - Fix #8352: A theme whose source directory no longer exists (e.g. a stale stored theme path) made
Theme::publishResources()andTheme::getBaseUrl()throw, aborting the request inTheme::register()before the #8335 fallback to the core theme could run — publishing such a theme is now logged and skipped instead - Fix #8352: Added
Theme::getPublishedBasePath(), the published counterpart ofTheme::getBasePath()— since the 1.19 move of the core theme intoprotected/humhub/themes(#8102) the theme source directory is outside the webroot, so anything served to the browser is only reachable below the published path.getPublishedBasePath()andpublishResources()now resolve through a single asset managerpublish()call, so the published path and the published URL can no longer refer to different published copies — the published directory name is derived from the modification time of the theme source directory, so resolving the path independently (viagetPublishedPath(), asgetPublishedResourcesPath()did) could return a stale directory, and returned an absolute path or a mount-relative one depending on whether the theme had already been published in the same request - Fix #8348: The installer, the admin welcome tour and the content-search CLI looked up the admin user (and welcome space) by the hardcoded id 1, which is null on a Galera/MariaDB cluster where the first inserted row does not get id 1 — the installer crashed on the final step
- Fix #8347: The web installer dropped custom PDO
attributes(e.g. SSL options) from the db config when testing/creating the database, so installs against a server that requires SSL failed with “SSL is required” - Fix #8345: A widget whose
init()threw an exception stayed permanently broken on its DOM node — the component instance is cached on the node beforeinit()runs, so every later initialization pass resolved the broken cached instance instead of retrying; a failed construction now removes the cached instance, letting the next pass initialize the widget again - Fix #8344: Module scripts served from a cross-origin
assetsmount (S3/CDNbaseUrl) executed asynchronously and out of document order when loaded with an ajax/pjax response — widgets initialized before their module registered (Required a non initialized module: …) and a module could run before a library it depends on (e.g. the space calendar’s FullCalendar bundle), breaking the first open of ajax-loaded views; scripts from the announced asset origins are now fetched through a synchronous XHR like same-origin scripts, restoring document-order execution (requires CORS headers on the asset host; without them a warning is logged and scripts fall back to in-order asynchronous execution) - Enh #8337: Added a mail (SMTP) delivery configuration step to the web installer (after the basic step) reusing the admin mailing settings form, with an inline “Test” button that verifies the entered settings via AJAX; configuring mail never blocks completion, and the step is skipped on automated/managed-hosting installs (fixed mail config)
- Fix #8343: The new installer mail step (#8337) did not appear under Docker, where the auto-setup flag only automates the technical setup while the config wizard still runs interactively — the step is now only skipped when the mail transport is pinned via static config
- Enh #8337: Added a mail (SMTP) delivery configuration step to the web installer (after the basic step) reusing the admin mailing settings form, with an inline “Test” button that verifies the entered settings via AJAX; configuring mail never blocks completion, and the step is skipped on managed-hosting installs (fixed mail config)
- Enh #8337: The
phpmail transport (native mail()/sendmail) is no longer offered under Docker (HUMHUB_DOCKER) — hidden in the mailing settings form and rejected in validation, since containers ship no local MTA - Enh #8336: Unified the two near-identical
UserModule.authtranslation keys for the maintenance mode message that differed only by a trailing period — the maintenance page heading now reuses the punctuated key, so the sentence no longer has to be translated twice - Enh #8339: The tour navigation buttons (Next/Previous/Done) and progress text are now translatable
- Fix #8335: The mailer view theme pointed at
@humhub/themes/Humhub(lowercaseh), a dead path on case-sensitive filesystems since the directory isHumHub— it now uses theTheme::CORE_THEME_NAMEconstant like the main view theme - Fix #8335: An update that moves the theme out of the webroot (the 1.19 move of
static/themesintoprotected/humhub, #8102) could leave an emptythemes/HumHubskeleton behind while the stored active theme still pointed at it — every request then failed with a fatal SCSS build error (“Can’t find stylesheet to import”) and the fallback looped forever because the empty skeleton shadowed the real core theme by name; a theme directory without itsscss/variables.scssis now ignored when resolving themes (so the stale path no longer loads and no longer shadows the core theme and affected installations self-heal), the theme CSS fallback only switches to and refreshes for a different, buildable core theme instead of risking an endless redirect loop, and a theme’svariablesimport is skipped when the file is missing - Fix #8351: SSO buttons can overflow on login page
- Fix #8360: A config file still setting the removed
modules.content.adminCanViewAllContent/adminCanEditAllContentoptions (replaced in 1.17 bymodules.admin.enableManageAllContentPermission) crashed every request with anUnknownPropertyExceptioninstead of a graceful warning — these keys are now stripped from the loaded config like other legacy settings and flagged on the Administration → Information page - Enh #7551: Add a “Create Space” button in the space directory page
- Fix #8364: The comment/reply “Attach Files” trigger is a non-focusable
<span>; clicking it dropped focus without moving it anywhere, which instantly hid the upload/submit button row again since it is only shown via:focus-within/:has()(#8318) — before the click’s own action could run, so opening the file picker either did nothing or made the row disappear while its dialog was open. The trigger now gets focus like the adjacent handler dropdown-toggle button viatabindex/role="button", and is keyboard-operable via Enter/Space; the button row also stays visible once a file has been attached, not just once the message has text - Enh #8372: Private content and private spaces are now hidden while impersonating a user, and each impersonation is logged — both configurable via the new
Yii::$app->user->impersonationcomponent; the impersonation state now fails closed (no auto-login cookie for the impersonated identity, only the impersonator’s id in the session) - Fix #8371: Fix mixed param type nullable by default in
ForceExplicitNullableParamRector - Fix #8383: Removed the unreachable
ContentContainerControllerAccess::RULE_CONTAINER_ACCESSvalidator (validateContainerAccess(),canAccessSpace(),getSpaceMembership(),canAccessUser()) — the rule was never added to any access rule set, so it never ran; the space/profile visibility checks it duplicated are already enforced by the container controller behaviors - Fix #8388: Fix styles of the widget “Latest activities”