NodeBB
Node.js based forum software built for the modern web
Alternative to: discourse, vanilla forums, circle
About
Versions (116)
v4.16.1
2026-10-02Release build (patch) of NodeBB @ 2026-10-02T14:50:56.233Z
v4.16.1 (2026-10-02)
Documentation Changes
- document missing chat room create and update fields (#14908) (77d9604a)
New Features
- let plugins map admin routes to privileges from static:privileges.admin.init (#14891) (527b8687)
- generic bodyShort for merged notifications with a plugin-registered mergeId (#14886) (d3c5e1d5)
- warn in the dashboard when a proxy is in front of an untrusting NodeBB (#14872) (3f479e8d)
- let plugins take part in notification merging (#14843) (6c9f017b)
- add a write API route for custom user fields (#14840) (39910850)
Bug Fixes
- category moderators see an empty post queue (#14943) (87f90bb3)
- closes #14942, fix undefined attachment (85a9892c)
- closes #14926, create indices when converting objects table (#14928) (2cd36780)
- update nodemailer and fix services (247b69b0)
- closes #14919, ignore @ suffixes in upload paths (6c82eec2)
- closes #14896, fix old user profile pictures (043e173d)
- category names not being translated in topic events (aa83b633)
- quote tooltip leaked into topics without reply privilege (#14910) (62a7c611)
- changing a public room’s groups left members who lost access in the room (#14906) (6cdb54b9)
- chat unread pushes kept going to the room’s old members (#14905) (3e53f1ae)
- rtlcss ignore directives were stripped before rtl processing (#14907) (ac21ac78)
- trigger reauth prompt on 401 status instead of translated message (#14914) (2ceb292f)
- only administrators and admin:users holders handle user flags (#14890) (b9121aab)
- deleting a group left public chat rooms restricted to its name (#14902) (7c232f6a)
- leaving a group removed users from the wrong public chat rooms (#14900) (6c4ecd3d)
- remove itemprop=“image” from buildAvatar (a5ef5103)
- closes #14894, services moved to a nested object (ad40ff63)
- chat message flag notifications went to global moderators (#14888) (97de7b82)
- don’t delete a tag when renaming it to a name that cleans up to itself (#14885) (d5376a0e)
- merge notifications that share a mergeId with no differentiator (#14871) (bd0b2535)
- translate name of custom fields like [[user:website]] [[user:location]] etc (99397176)
- merge notifications for flags on the same chat message (#14866) (a8d93e12)
- give merged post-queue notifications their own text (#14865) (593a71e1)
- merged user flag notifications show the flagged user (#14864) (e3cddfbc)
- apply the default email payload and text direction in sendToEmail (#14863) (97c0f022)
- bump 2factor (52297333)
- three ways a custom profile field could not be saved (#14846) (974fefd7)
- selection tooltip positioned offscreen for selections in code blocks (#14849) (a553d8bc)
- post queue notifications never merged (#14842) (15ef3719)
- allow one flag more per day than the configured limit (#14838) (5af369ac)
- drop the filename when an uploaded file has no extension (#14839) (17b202f9)
- match registration queue entries against unnormalised IPs (#14837) (b8d9cf9d)
- flag history labelled registration details as username/email changes (#14836) (572bb42f)
- unassigning a flag showed “Guest” as the new assignee (#14834) (a671ee20)
- activitypub: normalize non-array tag from remote actors in mocks (770037e9)
- security:
- reject array cid in createTopicFromPosts moderator gate (2be4c5c4)
- apply CSRF protection to the v3 JSON login route (d48df6d7)
- close post-queue existence oracle and bodyless DELETE crash (251e7bfa)
- return 404 instead of 403 for restricted topics/posts/feeds (b5fb06ac)
- categories: hide disabled categories from non-admins in get (88847e64)
- uploads: normalize post upload paths before storing and hashing (77944ac2)
- socket.io: always provide a callback for empty payloads (187c22e2)
Other Changes
- cache: fix key/enabled check for toggles (#14921) (e6d7672d)
Refactors
- add rejectUnauthorized support (1976827b)
- use the same style on group names in dropdown (4f4b1f28)
- flag assignment checks the same rule as flag access (#14889) (08f6f054)
- one owner for the email cancel gate (#14873) (58e1d449)
- one owner for the sortable ACP list editors (#14867) (3f1fbc62)
- one owner for db-backed rate limit counters (#14868) (dfb22b76)
- one owner for custom user field value parsing (#14862) (eb0f0eca)
- one owner for the custom user field type rules (#14860) (3757db29)
- one owner for the custom user field keys (#14853) (89e6b358)
- one client ip helper for both transports (#14844) (54ae3cc5)
Tests
- update assertions for oracle-closing status changes (34b5c915)