NodeBB logo

NodeBB

Node.js based forum software built for the modern web

Alternative to: discourse, vanilla forums, circle

NodeBB screenshot

About Versions (116)

v4.16.1

2026-10-02

Release build (patch) of NodeBB @ 2026-10-02T14:50:56.233Z

v4.16.1 (2026-10-02)

Documentation Changes
  • document missing chat room create and update fields (#14908) (77d9604a)
New Features
  • let plugins map admin routes to privileges from static:privileges.admin.init (#14891) (527b8687)
  • generic bodyShort for merged notifications with a plugin-registered mergeId (#14886) (d3c5e1d5)
  • warn in the dashboard when a proxy is in front of an untrusting NodeBB (#14872) (3f479e8d)
  • let plugins take part in notification merging (#14843) (6c9f017b)
  • add a write API route for custom user fields (#14840) (39910850)
Bug Fixes
  • category moderators see an empty post queue (#14943) (87f90bb3)
  • closes #14942, fix undefined attachment (85a9892c)
  • closes #14926, create indices when converting objects table (#14928) (2cd36780)
  • update nodemailer and fix services (247b69b0)
  • closes #14919, ignore @ suffixes in upload paths (6c82eec2)
  • closes #14896, fix old user profile pictures (043e173d)
  • category names not being translated in topic events (aa83b633)
  • quote tooltip leaked into topics without reply privilege (#14910) (62a7c611)
  • changing a public room’s groups left members who lost access in the room (#14906) (6cdb54b9)
  • chat unread pushes kept going to the room’s old members (#14905) (3e53f1ae)
  • rtlcss ignore directives were stripped before rtl processing (#14907) (ac21ac78)
  • trigger reauth prompt on 401 status instead of translated message (#14914) (2ceb292f)
  • only administrators and admin:users holders handle user flags (#14890) (b9121aab)
  • deleting a group left public chat rooms restricted to its name (#14902) (7c232f6a)
  • leaving a group removed users from the wrong public chat rooms (#14900) (6c4ecd3d)
  • remove itemprop=“image” from buildAvatar (a5ef5103)
  • closes #14894, services moved to a nested object (ad40ff63)
  • chat message flag notifications went to global moderators (#14888) (97de7b82)
  • don’t delete a tag when renaming it to a name that cleans up to itself (#14885) (d5376a0e)
  • merge notifications that share a mergeId with no differentiator (#14871) (bd0b2535)
  • translate name of custom fields like [[user:website]] [[user:location]] etc (99397176)
  • merge notifications for flags on the same chat message (#14866) (a8d93e12)
  • give merged post-queue notifications their own text (#14865) (593a71e1)
  • merged user flag notifications show the flagged user (#14864) (e3cddfbc)
  • apply the default email payload and text direction in sendToEmail (#14863) (97c0f022)
  • bump 2factor (52297333)
  • three ways a custom profile field could not be saved (#14846) (974fefd7)
  • selection tooltip positioned offscreen for selections in code blocks (#14849) (a553d8bc)
  • post queue notifications never merged (#14842) (15ef3719)
  • allow one flag more per day than the configured limit (#14838) (5af369ac)
  • drop the filename when an uploaded file has no extension (#14839) (17b202f9)
  • match registration queue entries against unnormalised IPs (#14837) (b8d9cf9d)
  • flag history labelled registration details as username/email changes (#14836) (572bb42f)
  • unassigning a flag showed “Guest” as the new assignee (#14834) (a671ee20)
  • activitypub: normalize non-array tag from remote actors in mocks (770037e9)
  • security:
    • reject array cid in createTopicFromPosts moderator gate (2be4c5c4)
    • apply CSRF protection to the v3 JSON login route (d48df6d7)
    • close post-queue existence oracle and bodyless DELETE crash (251e7bfa)
    • return 404 instead of 403 for restricted topics/posts/feeds (b5fb06ac)
  • categories: hide disabled categories from non-admins in get (88847e64)
  • uploads: normalize post upload paths before storing and hashing (77944ac2)
  • socket.io: always provide a callback for empty payloads (187c22e2)
Other Changes
  • cache: fix key/enabled check for toggles (#14921) (e6d7672d)
Refactors
  • add rejectUnauthorized support (1976827b)
  • use the same style on group names in dropdown (4f4b1f28)
  • flag assignment checks the same rule as flag access (#14889) (08f6f054)
  • one owner for the email cancel gate (#14873) (58e1d449)
  • one owner for the sortable ACP list editors (#14867) (3f1fbc62)
  • one owner for db-backed rate limit counters (#14868) (dfb22b76)
  • one owner for custom user field value parsing (#14862) (eb0f0eca)
  • one owner for the custom user field type rules (#14860) (3757db29)
  • one owner for the custom user field keys (#14853) (89e6b358)
  • one client ip helper for both transports (#14844) (54ae3cc5)
Tests
  • update assertions for oracle-closing status changes (34b5c915)