This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
Summary
AI summaryUpdates Plugin platform, Plugin security, and Collections, files & wallet across a mixed release.
Full changelog
Plugins go from read-mostly observers to a real extension platform: they can now write to the itinerary, contribute native data, react to core events, add whole planner tabs, and match TREK's look — all behind the same sandboxed, permission-gated boundary. Plus budget, collections, files, guest and mobile fixes. No breaking changes — every new capability is opt-in and admin-consented; existing plugins keep working.
Plugins: 3.2.0 vs 3.2.1
Please consult the wiki for more information.
| Capability | 3.2.0 | 3.2.1 |
|---|---|---|
| Usable permissions | ~8 | ~18 |
| Write / mutate methods | 1 (costs.create) | ~16 — costs C/U/D, places C/U/D, days C/U/D, itinerary assign/unassign, trips.update, metadata C/U/D |
| Provider hooks | 0 (declared but dead) | 2 live — placeDetailProvider, warningProvider (+ invoke.hook transport) |
| Event subscriptions | — | events:subscribe (name + trip only) |
| Read subsystems | trips, costs, users | + packing, files |
| Entity metadata | — | db:meta (no schema fork) |
| UI extension points | slots sidebar/hero, pages | + trip-page type, + place-detail slot |
| Design & DX | minimal | UI design kit, window.trek.ui, typed SDK, Cookbook + example |
| Distribution | registry install | + sideload .zip, registry force-refresh |
| Plugin dependency | — | Inter plugin dependencies (for potential plugin libraries) |
| Addon dependency | — | Ensure specific addon is enabled |
Plugin platform
- Permission-gated planner write APIs (places, days, itinerary, trips), each gated by the acting user's own
*_editpermission (#1429) trip-pageplugins (a tab inside every trip) and aplace-detailwidget slot- Provider hooks wired:
placeDetailProviderandwarningProvider, also atGET /api/place-details/:idand/api/trip-warnings/:id - Core event subscriptions (
events:subscribe) — react toplace:*,day:*,budget:*,file:*, … - Entity metadata (
db:meta) — per-plugin key/value store on trips/places/days - Broader reads:
ctx.packing.list/ctx.files.list; costs read + write (get/list/create/update/delete) - TREK UI design kit (
<!-- trek:ui -->→ tokens, glass, dark-mode, accent, appearance flags,window.trek), native scaffold, themed dev preview, auto-height glassy cards - Author DX: typed
ctxreturns,window.trek.uiDOM helpers, Plugin Cookbook +trip-doctorexample,clack/promptsCLI - Sideload a plugin by uploading a
.zip; force-refresh the registry
Plugin security
- Open redirect prevented in the plugin route proxy
hook:*grant enforced — implementing a hook isn't enough without the consentpacking.listrespects per-user visibility (#858) — no leaking another member's private items- IPC parent/child sealed, arbitrary API access blocked, full capability surface hardened + tested
Budget & costs
- FX rate frozen on every cost and settlement write, so a later rate drift can't re-open a settled position (#1445)
- New "Outstanding amount" card
Collections, files & wallet
- Editing a saved place no longer resets its status to "idea"
- Save picker shows above the mobile place detail
- Apple Wallet
.pkpassessupported, incl. booking uploads and the files tab (#1447, #1448)
Guests
- Guest names are per-trip again — the same friend can be "Jake" on two trips instead of being auto-renamed to "Jake 2" (#1446)
Planner & mobile
- Drag & drop disabled on mobile so the places list scrolls
- Day-plan collapse state persists after closing the page
- Remove-from-day button is icon-only on mobile (#1432)
Other
- Keep stored settings when an update fails; Unsplash API key usage fixed
- Translation fixes (Vietnamese "Disabled", remaining new keys across 22 locales)
- Added a Code of Conduct
Full changelog: https://github.com/mauriceboe/TREK/compare/v3.2.0...v3.2.1
Security Fixes
- Prevented open redirect in plugin route proxy; enforced `hook:*` grant consent; sealed IPC parent/child communication and hardened arbitrary API access.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]