· 10 years ago · Mar 23, 2016, 02:36 PM
1v1.3
2
3ES2015/Modules
4
5Enable ES2015 and CommonJS modules in Meteor apps and packages, on both client and server. Also let you install modules in apps and package by running npm install. XXX link to paper document
6
7Enable ES2015 generators and ES2016 async/await in the ecmascript package.
8
9Inherit static getters and setters in subclasses, when using the ecmascript package. #5624
10
11Report full file paths on compiler errors when using the ecmascript package. #5551
12
13Now possible to import or require files with a .json file extension. #5810
14
15process.env.NODE_ENV is now defined on both client and server as either development or production, which also determines the boolean flags Meteor.isDevelopment and Meteor.isProduction.
16
17Absolute identifiers for app modules no longer have the /app/ prefix, and absolute identifiers for Meteor packages now have the prefix /node_modules/meteor/ instead of just /node_modules/, meaning you should import {Blaze} from "meteor/blaze" instead of from "blaze".
18
19Package variables imported by application code are once again exposed globally, allowing them to be accessed from the browser console or from meteor shell. #5868
20
21Fixed global variable assignment analysis during linking. #5870 #5819
22
23Changes to files in node_modules will now trigger a restart of the development server, just like any other file changes. #5815
24
25The meteor package now exports a global variable (a la Node) that provides a reliable reference to the global object for all Meteor code.
26
27Packages in local node_modules directories now take precedence over Meteor packages of the same name. #5933
28
29Upgraded babel-compiler to Babel 6, with the following set of plugins: https://github.com/meteor/babel-preset-meteor/blob/master/index.js
30
31Lazy CSS modules may now be imported by JS: 12c946ee651a93725f243f790c7919de3d445a19
32
33Packages in the top-level node_modules directory of an app can now be imported by Meteor packages: c631d3ac35f5ca418b93c454f521989855b8ec72
34
35Added support for wildcard import and export statements. #5872 #5897
36
37Client-side stubs for built-in Node modules are now provided automatically if the meteor-node-stubs npm package is installed. #6056
38
39Imported file extensions are now optional for file types handled by compiler plugins. #6151
40
41Upgraded Babel packages to ~6.5.0: 292824da3f8449afd1cd39fcd71acd415c809c0f Note: .babelrc files are now ignored (#6016), but may be reenabled (#6351).
42
43Polyfills now provided for process.nextTick and process.platform. #6167 #6198 #6055 efe53de492da6df785f1cbef2799d1d2b492a939
44
45The meteor test-app command is now meteor test [--full-app]: ab5ab15768136d55c76d51072e746d80b45ec181
46
47New apps now include a package.json file. c51b8cf7ffd8e7c9ca93768a2df93e4b552c199c
48
49require.resolve is now supported. https://github.com/benjamn/install/commit/ff6b25d6b5511d8a92930da41db73b93eb1d6cf8
50
51JSX now enabled in .js files processed by the ecmascript compiler plugin. #6151
52
53On the server, modules contained within node_modules directories are now loaded using the native Node require function. #6398
54
55All <script> tag(s) for application and package code now appear at the end of the <body> rather than in the <head>. #6375
56
57The client-side version of process.env.NODE_ENV (and other environment variables) now matches the corresponding server-side values. #6399
58
59Performance
60
61Don't reload package catalog from disk on rebuilds unless package dependencies changed. #5747
62
63Improve minimongo performance on updating documents when there are many active observes. #5627
64
65Platform
66
67Upgrade to Node v0.10.41.
68
69Allow all types of URLs that npm supports in Npm.depends declarations.
70
71Split up standard-minifiers in separate CSS (standard-minifiers-css) and JS minifiers (standard-minifiers-js). standard-minifiers now acts as an umbrella package for these 2 minifiers.
72
73Allow piping commands to meteor shell via STDIN. #5575
74
75Let users set the CAFILE environment variable to override the SSL root certificate list. #4757 #5523
76
77force-ssl is now marked production only.
78
79Cordova
80
81Cordova dependencies have been upgraded to the latest versions (cordova-lib 6.0.0, cordova-ios 4.0.1, and cordova-android 5.1.0).
82
83iOS apps now require iOS 8 or higher, and building for iOS requires Xcode 7.2 to be installed.
84
85Building for Android now requires Android SDK 23 to be installed. You may also need to create a new AVD for the emulator.
86
87Building Cordova Android apps on Windows is now supported. #4155
88
89The Crosswalk plugin has been updated to 1.4.0.
90
91Cordova core plugins are now pinned to minimal versions known to be compatible with the included platforms. A warning is printed asking people to upgrade their dependencies if they specify an older version, but we'll always use the pinned version regardless.
92
93The plugin used for file serving and hot code push has been completely rewritten. Among many other improvements, it downloads updates incrementally, can recover from downloading faulty JavaScript code, and is much more reliable and performant. See cordova-plugin-meteor-webapp for more a more detailed description of the new design.
94
95If the callbacks added with Meteor.startup() do not complete within a set time, we consider a downloaded version faulty and will fallback to the last known good version. The default timeout is 20 seconds, but this can be configured by setting App.setPreference("WebAppStartupTimeout", "10000"); (in milliseconds) in mobile-config.js.
96
97We now use WKWebView on iOS by default, even on iOS 8 (which works because we do not use file:// URLs).
98
99We now use localhost instead of meteor.local to serve files from. Since localhost is considered a secure origin, this means the web view won't disable web platform features that it otherwise would.
100
101The local server port now lies between 12000-13000 and is chosen based on the appId, to both be consistent and lessen the chance of collisions between multiple Meteor Cordova apps installed on the same device.
102
103The plugin now allows for local file access on both iOS and Android, using a special URL prefix (http://localhost:<port>/local-filesystem/<path>).
104
105App icon and launch image sizes have been updated. Low resolution sizes for now unsupported devices have been deprecated, and higher resolution versions have been added.
106
107We now support the modern Cordova whitelist mechanism. App.accessRule has been updated with new options.
108
109meteor build now supports a --server-only option to avoid building the mobile apps when ios or android platforms have been added. It still builds the web.cordova architecture in the server bundle however, so it can be served for hot code pushes.
110
111meteor run now always tries to use an autodetected IP address as the mobile ROOT_URL, even if we're not running on a device. This avoids a situation where an app already installed on a device connects to a restarted development server and receives a localhost ROOT_URL. #5973
112
113Fixed a discrepancy between the way we calculated client hashes during a mobile build and on the server, which meant a Cordova app would always download a new version the first time it started up.
114
115In Cordova apps, Meteor.startup() now correctly waits for the device to be ready before firing the callback.
116
117Accounts
118
119Make Accounts.forgotPassword treat emails as case insensitive, as the rest of the accounts system does.
120Blaze
121
122Don't throw in certain cases when calling a template helper with an empty data context. #5411 #5736
123
124Improve automatic blocking of URLs in attribute values to also include vbscript: URLs.
125
126Testing
127
128Packages can now be marked as testOnly to only run as part of app testing with meteor test. This is achieved by setting testOnly: true to Package.describe.
129Uncategorized
130
131Remove warning in the simple-todos-react example app. #5716
132
133Fix interaction between browser-policy and oauth packages. #5628
134
135Add README.md to the tinytest package. #5750
136
137Don't crash when calling ReactiveDict.prototype.clear if a property with a value wasn't previously accessed. #5530 #5602
138
139Move DDPRateLimiter to the server only, since it won't work if it is called from the client. It will now error if referenced from the client at all.
140
141Don't call function more than once when passing a Match.Where argument to check. #5630 #5651
142
143Fix empty object argument check in this.subscribe in templates. #5620
144
145Make HTTP.call not crash on undefined content. #5565 #5601
146
147Return observe handle from Mongo.Collection.prototype._publishCursor. #4983 #5615
148
149Add 'Did you mean?' reminders for some CLI commands to help Rails developers. #5593
150
151Make internal shell scripts compatible with other Unix-like systems. #5585
152
153Add a _pollingInterval option to coll.find() that can be used in conjunction with _disableOplog: true. #5586
154
155Expose Tinytest internals which can be used to extend it. #3541
156
157Improve error message from check when passing in null. #5545
158
159Split up standard-minifiers in separate CSS (standard-minifier-css) and JS minifiers(standard-minifier-js). standard-minifiers now acts as an umbrella package for these 2 minifiers.
160
161Detect new Facebook user-agent in the spiderable package. #5516
162
163Match.ObjectIncluding now really requires plain objects. #6140
164
165Allow git+ URL schemes for npm dependencies. #844
166
167Expose options disableOplog, pollingIntervalMs, and pollingThrottleMs to Cursor.find for tuning observe parameters on the server.
168
169Expose dynamicHead and dynamicBody hooks in boilerplate generation allowing code to inject content into the body and head tags from the server. #3860
170
171Add methods of the form BrowserPolicy.content.allowBlobUrl() to BrowserPolicy #5141
172
173Move <script> tags to end of to enable 'loading' UI to be inserted into the boilerplate #6375
174
175Adds WebAppInternals.setBundledJsCssUrlRewriteHook allowing apps to supply a hook function that can create a dynamic bundledJsCssPrefix at runtime. This is useful if you're using a CDN by giving you a way to ensure the CDN won't cache broken js/css resources during an app upgrade.
176
177Patches contributed by GitHub users vereed, mitar, nathan-muir, robfallows, skishore, okland, Primigenus, zimme, welelay, rgoomar, bySabi, mbrookes, TomFreudenberg, TechPlexEngineer, zacharydenton, AlexeyMK, gwendall, dandv, devgrok, brianlukoff.
178
179v.1.2.1, 2015-Oct-26
180
181coll.insert() now uses a faster (but cryptographically insecure) algorithm to generate document IDs when called outside of a method and an _id field is not explicitly passed. With this change, there are no longer two algorithms used to generate document IDs. Random.id() can still be used to generate cryptographically secure document IDs. #5161
182
183The ecmascript-collections package has been renamed to ecmascript-runtime and now includes a more complete selection of ES2015 polyfills and shims from core-js. The complete list can be found here.
184
185Check type of onException argument to bindEnvironment. #5271
186
187WebApp's PORT environment variable can now be a named pipe to better support deployment on IIS on Windows. 4413
188
189Template.dynamic can be now used as a block helper: {{#Template.dynamic}} ... {{/Template.dynamic}} #4756
190
191Collection#allow/deny now throw errors when passed falsy values. #5442
192
193source-map has been updated to a newer patch version, which fixes major bugs in particular around loading bundles generated by Webpack. #5411
194
195check now returns instead of throwing errors internally, which should make it much faster. check is used in many core Meteor packages, so this should result in small performance improvements across the framework. #4584
196
197The userEmail option to Meteor.loginWithMeteorDeveloperAccount has been renamed to loginHint, and now supports Google accounts as well. The old option still works for backwards compatibility. #2422 #5313
198
199The old addFiles API for adding package assets no longer throws an error, making it easier to share packages between pre- and post-1.2 versions of Meteor. #5458
200
201Normally, you can't deploy to free meteor.com hosting or Galaxy from a non-Linux machine if you have local non-published packages with binary dependencies, nor can you run meteor build --architecture SomeOtherArch. As a temporary workaround, if you set the METEOR_BINARY_DEP_WORKAROUND variable, you will be able to deploy to Galaxy (but not free meteor.com hosting), and tarballs built with meteor build will contain a programs/server/setup.sh shell script which should be run on the server to install those packages.
202
203v1.2.0.2, 2015-Sept-28
204
205Update Crosswalk plugin for Cordova to 1.3.1. #5267
206
207Fix meteor add for a Cordova plugin using a Git URL with SHA.
208
209Upgraded the promise package to use meteor-promise@0.5.0, which uses the global Promise constructor in browsers that define it natively.
210
211Fix error in assigning attributes to <body> tag when using Blaze templates or static-html. #5232
212
213v1.2.0.1, 2015-Sept-22
214
215Fix incorrect publishing of packages with exports but no source. #5228
216v1.2, 2015-Sept-21
217
218There are quite a lot of changes in Meteor 1.2. See the Wiki for a shorter list of breaking changes you should be aware of when upgrading.
219
220Core Packages
221
222meteor-platform has been deprecated in favor of the smaller meteor-base, with apps listing their other dependencies explicitly. The v1.2 upgrader will rewrite meteor-platform in existing apps. meteor-base puts fewer symbols in the global namepsace, so it's no longer true that all apps have symbols like Random and EJSON in the global namespace.
223
224New packages: ecmascript, es5-shim, ecmascript-collections, promise, static-html, jshint, babel-compiler
225
226No longer include the json package by default, which contains code for JSON.parse and JSON.stringify. (The last browser to not support JSON natively was Internet Explorer 7.)
227
228autoupdate has been renamed hot-code-push
229
230Meteor Accounts
231
232Login attempts are now rate-limited by default. This can be turned off using Accounts.removeDefaultRateLimit().
233
234loginWithPassword now matches username or email in a case insensitive manner. If there are multiple users with a username or email only differing in case, a case sensitive match is required. #550
235
236loginWithGithub now requests user:email scope by default, and attempts to fetch the user's emails. If no public email has been set, we use the primary email instead. We also store the complete list of emails. #4545
237
238When an account's email address is verified, deactivate other verification tokens. #4626
239
240Fix bug where blank page is shown when an expired login token is present. #4825
241
242Fix OAuth1Binding.prototype.call when making requests to Twitter with a large parameter set.
243
244Directions for setting up Google OAuth in accounts-ui have been updated to match Google's new requirements.
245
246Add Accounts.oauth.unregisterService method, and ensure that users can only log in with currently registered services. #4014
247
248The accounts-base now defines reusable AccountsClient and AccountsServer constructors, so that users can create multiple independent instances of the Accounts namespace. #4233
249
250Create an index for Meteor.users on services.email.verificationTokens.token (instead of emails.validationTokens.token, which never was used for anything). #4482
251
252Remove an IE7-specific workaround from accounts-ui. #4485
253
254Livequery
255
256Improved server performance by reducing overhead of processing oplog after database writes. Improvements are most noticeable in case when a method is doing a lot of writes on collections with plenty of active observers. #4694
257Mobile
258
259The included Cordova tools have been updated to the latest version 5.2.0. This includes Cordova Android 4.1 and Cordova iOS 3.9. These updates may require you to make changes to your app. For details, see the Cordova release notes for for the different versions.
260
261Thanks to Cordova Android's support for pluggable web views, it is now possible to install the Crosswalk plugin, which offers a hugely improved web view on older Android versions. You can add the plugin to your app with meteor add crosswalk.
262
263The bundled Android tools have been removed and a system-wide install of the Android SDK is now required. This should make it easier to keep the development toolchain up to date and helps avoid some difficult to diagnose failures. If you don't have your own Android tools installed already, you can find more information about installing the Android SDK for Mac or Linux.
264
265As part of moving to npm, many Cordova plugins have been renamed. Meteor should perform conversions automatically, but you may want to be aware of this to avoid surprises. See here for more information.
266
267Installing plugins from the local filesystem is now supported using file:// URLs, which should make developing your own plugins more convenient. It is also needed as a temporary workaround for using the Facebook plugin. Relative references are interpreted relative to the Meteor project directory. (As an example, meteor add cordova:phonegap-facebook-plugin@file://../phonegap-facebook-plugin would attempt to install the plugin from the same directory you Meteor project directory is located in.)
268
269Meteor no longer supports installing Cordova plugins from tarball URLs, but does support Git URLs with a SHA reference (like https://github.com/apache/cordova-plugin-file#c452f1a67f41cb1165c92555f0e721fbb07329cc). Existing GitHub tarball URLs are converted automatically.
270
271Allow specifying a buildNumber in App.info, which is used to set the android-versionCode and ios-CFBundleVersion in the config.xml of the Cordova project. The build number is used to differentiate between different versions of the app, and should be incremented before distributing a built app to stores or testing services. #4048
272
273Other changes include performance enhancements when building and running, and improved requirements checking and error reporting.
274
275Known issue: we do not currently show logging output when running on the iOS Simulator. As a workaround, you can meteor run ios-device to open the project in Xcode and watch the output there.
276
277Templates/Blaze
278
279New syntax: Handlebars sub-expressions are now supported -- as in, {{helper (anotherHelper arg1 arg2)}} -- as well as new block helper forms #each .. in .. and #let x=y. See https://github.com/meteor/meteor/tree/devel/packages/spacebars
280
281Add a special case for the new react-template-helper package -- don't let templates use {{> React}} with siblings since React.render assumes it's being rendered into an empty container element. (This lets us throw the error when compiling templates rather than when the app runs.)
282
283Improve parsing of <script> and <style> tags. #3797
284
285Fix a bug in observe-sequence. The bug was causing unnecessary rerenderings in an instance of #each block helper followed by false "duplicate ids" warnings. #4049
286
287TemplateInstance#subscribe now has a new connection option, which specifies which connection should be used when making the subscription. The default is Meteor.connection, which is the connection used when calling Meteor.subscribe.
288
289Fix external <script> tags in body or templates. #4415
290
291Fix memory leak. #4289
292
293Avoid recursion when materializing DOM elements, to avoid stack overflow errors in certain browsers. #3028
294
295Blaze and Meteor's built-in templating are now removable using meteor remove blaze-html-templates. You can add back support for static head and body tags in .html files by using the static-html package.
296
297DDP
298
299Websockets now support the permessage-deflate extension, which compresses data on the wire. It is enabled by default on the server. To disable it, set $SERVER_WEBSOCKET_COMPRESSION to 0. To configure compression options, set $SERVER_WEBSOCKET_COMPRESSION to a JSON object that will be used as an argument to deflate.configure. Compression is supported on the client side by Meteor's Node DDP client and by browsers including Chrome, Safari, and Firefox 37.
300
301The ddp package has been split into ddp-client and ddp-server packages; using ddp is equivalent to using both. This allows you to use the Node DDP client without adding the DDP server to your app. #4191 #3452
302
303On the client, Meteor.call now takes a throwStubExceptions option; if set, exceptions thrown by method stubs will be thrown instead of logged, and the method will not be invoked on the server. #4202
304
305sub.ready() should return true inside that subscription's onReady callback. #4614
306
307Fix method calls causing broken state when socket is reconnecting. #5104
308
309Isobuild
310
311Build plugins will no longer process files whose names match the extension exactly (with no extra dot). If your build plugin needs to match filenames exactly, you should use the new build plugin API in this release which supplies a special filenames option. #3985
312
313Adding the same file twice in the same package is now an error. Previously, this could either lead to the file being included multiple times, or to a build time crash.
314
315You may now specify the bare option for JavaScript files on the server. Previous versions only allowed this on the client. #3681
316
317Ignore node_modules directories in apps instead of processing them as Meteor source code. #4457 #4452
318
319Backwards-incompatible change for package authors: Static assets in package.js files must now be explicitly declared by using addAssets instead of addFiles. Previously, any file that didn't have a source handler was automatically registered as a server-side asset. The isAsset option to addFiles is also deprecated in favor of addAssets.
320
321Built files are now always annotated with line number comments, to improve the debugging experience in browsers that don't support source maps.
322
323There is a completely new API for defining build plugins that cache their output. There are now special APIs for defining linters and minifiers in addition to compilers. The core Meteor packages for less, coffee, stylus and html files have been updated to use this new API. Read more on the Wiki page.
324
325CSS
326
327LESS and Stylus now support cross-package imports.
328
329CSS concatenation and minification is delegated to the standard-minifiers package, which is present by default (and added to existing apps by the v1.2 upgrader).
330
331CSS output is now split into multiple stylesheets to avoid hitting limits on rules per stylesheet in certain versions of Internet Explorer. #1876
332
333Mongo
334
335The oplog observe driver now properly updates queries when you drop a database. #3847
336
337MongoID logic has been moved out of minimongo into a new package called mongo-id.
338
339Fix Mongo upserts with dotted keys in selector. #4522
340
341meteor command-line tool
342
343You can now create three new example apps with the command line tool. These are the apps from the official tutorials at http://meteor.com/tutorials, which demonstrate building the same app with Blaze, Angular, and React. Try these apps with:
344
345meteor create --example simple-todos
346meteor create --example simple-todos-react
347meteor create --example simple-todos-angular
348meteor shell no longer crashes when piped from another command.
349
350Avoid a race condition in meteor --test and work with newer versions of the Velocity package. #3957
351
352Improve error handling when publishing packages. #3977
353
354Improve messaging around publishing binary packages. #3961
355
356Preserve the value of _ in meteor shell. #4010
357
358meteor mongo now works on OS X when certain non-ASCII characters are in the pathname, as long as the pgrep utility is installed (it ships standard with OS X 10.8 and newer). #3999
359
360meteor run no longer ignores (and often reverts) external changes to .meteor/versions which occur while the process is running. #3582
361
362Fix crash when downloading two builds of the same package version simultaneously. #4163
363
364Improve messages printed by meteor update, displaying list of packages that are not at the latest version available.
365
366When determining file load order, split file paths on path separator before comparing path components alphabetically. #4300
367
368Fix inability to run mongod due to lack of locale configuration on some platforms, and improve error message if the failure still occurs. #4019
369
370New meteor lint command.
371
372Minimongo
373
374The $push query modifier now supports a $position argument. #4312
375
376c.update(selector, replacementDoc) no longer shares mutable state between replacementDoc and Minimongo internals. #4377
377
378Email
379
380Email.send now has a new option, attachments, in the same style as mailcomposer. Details here.
381Tracker
382
383New Tracker.Computation#onStop method. #3915
384
385ReactiveDict has two new methods, clear and all. clear resets the dictionary as if no items had been added, meaning all calls to get will return undefined. all converts the dictionary into a regular JavaScript object with a snapshot of the keys and values. Inside an autorun, all registers a dependency on any changes to the dictionary. #3135
386
387Utilities
388
389New beforeSend option to HTTP.call on the client allows you to directly access the XMLHttpRequest object and abort the call. #4419 #3243 #3266
390
391Parse application/javascript and application/x-javascript HTTP replies as JSON too. #4595
392
393Match.test from the check package now properly compares boolean literals, just like it does with Numbers and Strings. This applies to the check function as well.
394
395Provide direct access to the mailcomposer npm module used by the email package on EmailInternals.NpmModules. Allow specifying a MailComposer object to Email.send instead of individual options. #4209
396
397Expose Spiderable.requestTimeoutMs from spiderable package to allow apps to set the timeout for running phantomjs.
398
399The spiderable package now reports the URL it's trying to fetch on failure.
400
401Other bug fixes and improvements
402
403Upgraded dependencies:
404
405Node: 0.10.40 (from 0.10.36)
406uglify-js: 2.4.20 (from 2.4.17)
407http-proxy: 1.11.1 (from 1.6.0)
408Meteor.loginWithGoogle now supports prompt. Choose a prompt to always be displayed on Google login.
409
410Upgraded coffeescript package to depend on NPM packages coffeescript@1.9.2 and source-map@0.4.2. #4302
411
412Upgraded fastclick to 1.0.6 to fix an issue in iOS Safari. #4393
413
414Fix Error: Can't render headers after they are sent to the client. #4253 #4750
415
416Meteor.settings.public is always available on client and server, and modifications made on the server (for example, during app initialization) affect the value seen by connecting clients. #4704
417
418Windows
419
420Increase the buffer size for netstat when looking for running Mongo servers. #4125
421
422The Windows installer now always fetches the latest available version of Meteor at runtime, so that it doesn't need to be recompiled for every release.
423
424Fix crash in meteor mongo on Windows. #4711
425
426v1.1.0.3, 2015-Aug-03
427
428Accounts
429
430When using Facebook API version 2.4, properly fetch email and other fields. Facebook recently forced all new apps to use version 2.4 of their API. #4743
431v1.1.0.2, 2015-Apr-06
432
433meteor command-line tool
434
435Revert a change in 1.1.0.1 that caused meteor mongo to fail on some Linux systems. #4115, #4124, #4134
436v1.1.0.1, 2015-Apr-02
437
438Blaze
439
440Fix a regression in 1.1 in Blaze Templates: an error happening when View is invalidated immediately, causing a client-side crash (accessing destroyMembers of undefined). #4097
441v1.1, 2015-Mar-31
442
443Windows Support
444
445The Meteor command line tool now officially supports Windows 7, Windows 8.1, Windows Server 2008, and Windows Server 2012. It can run from PowerShell or Command Prompt.
446
447There is a native Windows installer that will be available for download from https://www.meteor.com/install starting with this release.
448
449In this release, Meteor on Windows supports all features available on Linux and Mac except building mobile apps with PhoneGap/Cordova.
450
451The meteor admin get-machine command now supports an additional architecture, os.windows.x86_32, which can be used to build binary packages for Windows.
452
453Version Solver
454
455The code that selects compatible package versions for meteor update and resolves conflicts on meteor add has been rewritten from the ground up. The core solver algorithm is now based on MiniSat, an open-source SAT solver, improving performance and maintainability.
456
457Refresh the catalog instead of downgrading packages when the versions in .meteor/versions aren't in the cache. #3653
458
459Don't downgrade packages listed in .meteor/packages, or upgrade to a new major version, unless the new flag --allow-incompatible-update is passed as an override.
460
461Error messages are more detailed when constraints are unsatisfiable.
462
463Prefer "patched" versions of new indirect dependencies, and take patches to them on meteor update (for example, 1.0.1 or 1.0.0_1 over 1.0.0).
464
465Version Solver is instrumented for profiling (METEOR_PROFILE=1 in the environment).
466
467Setting the METEOR_PRINT_CONSTRAINT_SOLVER_INPUT environment variable prints information useful for diagnosing constraint solver bugs.
468
469Tracker
470
471Schedule the flush cycle using a better technique than setTimeout when available. #3889
472
473Yield to the event loop during the flush cycle, unless we're executing a synchronous Tracker.flush(). #3901
474
475Fix error reporting not being source-mapped properly. #3655
476
477Introduce a new option for Tracker.autorun - onError. This callback can be used to handle errors caught in the reactive computations. #3822
478
479Blaze
480
481Fix stack overflow from nested templates and helpers by avoiding recursion during rendering. #3028
482meteor command-line tool
483
484Don't fail if npm prints more than 200K. #3887
485Other bug fixes and improvements
486
487Upgraded dependencies:
488
489uglify-js: 2.4.17 (from 2.4.13)
490Patches contributed by GitHub users hwillson, mitar, murillo128, Primigenus, rjakobsson, and tmeasday.
491
492v1.0.5, 2015-Mar-25
493
494This version of Meteor now uses version 2.2 of the Facebook API for authentication, instead of 1.0. If you use additional Facebook API methods beyond login, you may need to request new permissions.
495
496Facebook will automatically switch all apps to API version 2.0 on April 30th, 2015. Please make sure to update your application's permissions and API calls by that date.
497
498For more details, see https://github.com/meteor/meteor/wiki/Facebook-Graph-API-Upgrade
499
500v1.0.4.2, 2015-Mar-20
501
502Fix regression in 1.0.4 where using Cordova for the first time in a project with hyphens in its directory name would fail. #3950
503v1.0.4.1, 2015-Mar-18
504
505Fix regression in 1.0.4 where meteor publish-for-arch only worked for packages without colons in their name. #3951
506v1.0.4, 2015-Mar-17
507
508Mongo Driver
509
510Meteor is now tested against MongoDB 2.6 by default (and the bundled version used by meteor run has been upgraded). It should still work fine with MongoDB 2.4. Previous versions of Meteor mostly worked with MongoDB 2.6, with a few caveats:
511
512Some upsert invocations did not work with MongoDB in previous versions of Meteor.
513Previous versions of Meteor required setting up a special "user-defined role" with access to the system.replset table to use the oplog observe driver with MongoDB 2.6. These extra permissions are not required with this version of Meteor.
514The MongoDB command needed to set up user permissions for the oplog observe driver is slightly different in MongoDB 2.6; see https://github.com/meteor/meteor/wiki/Oplog-Observe-Driver for details.
515
516We have also tested Meteor against the recently-released MongoDB 3.0.0. While we are not shipping MongoDB 3.0 with Meteor in this release (preferring to wait until its deployment is more widespread), we believe that Meteor 1.0.4 apps will work fine when used with MongoDB 3.0.0 servers.
517
518Fix 0.8.1 regression where failure to connect to Mongo at startup would log a message but otherwise be ignored. Now it crashes the process, as it did before 0.8.1. #3038
519
520Use correct transform for allow/deny rules in update when different rules have different transforms. #3108
521
522Provide direct access to the collection and database objects from the npm Mongo driver via new rawCollection and rawDatabase methods on Mongo.Collection. #3640
523
524Observing or publishing an invalid query now throws an error instead of effectively hanging the server. #2534
525
526Livequery
527
528If the oplog observe driver gets too far behind in processing the oplog, skip entries and re-poll queries instead of trying to keep up. #2668
529
530Optimize common cases faced by the "crossbar" data structure (used by oplog tailing and DDP method write tracking). #3697
531
532The oplog observe driver recovers from failed attempts to apply the modifier from the oplog (eg, because of empty field names).
533
534Minimongo
535
536When acting as an insert, c.upsert({_id: 'x'}, {foo: 1}) now uses the _id of 'x' rather than a random _id in the Minimongo implementation of upsert, just like it does for c.upsert({_id: 'x'}, {$set: {foo: 1}}). (The previous behavior matched a bug in the MongoDB 2.4 implementation of upsert that is fixed in MongoDB 2.6.) #2278
537
538Avoid unnecessary work while paused in minimongo.
539
540Fix bugs related to observing queries with field filters: changed callbacks should not trigger unless a field in the filter has changed, and changed callbacks need to trigger when a parent of an included field is unset. #2254 #3571
541
542Disallow setting fields with empty names in minimongo, to match MongoDB 2.6 semantics.
543
544DDP
545
546Subscription handles returned from Meteor.subscribe and TemplateInstance#subscribe now have a subscriptionId property to identify which subscription the handle is for.
547
548The onError callback to Meteor.subscribe has been replaced with a more general onStop callback that has an error as an optional first argument. The onStop callback is called when the subscription is terminated for any reason. onError is still supported for backwards compatibility. #1461
549
550The return value from a server-side Meteor.call or Meteor.apply is now a clone of what the function returned rather than sharing mutable state. #3201
551
552Make it easier to use the Node DDP client implementation without running a web server too. #3452
553
554Blaze
555
556Template instances now have a subscribe method that functions exactly like Meteor.subscribe, but stops the subscription when the template is destroyed. There is a new method on Template instances called subscriptionsReady() which is a reactive function that returns true when all of the subscriptions made with TemplateInstance#subscribe are ready. There is also a built-in helper that returns the same thing and can be accessed with Template.subscriptionsReady inside any template.
557
558Add onRendered, onCreated, and onDestroyed methods to Template. Assignments to Template.foo.rendered and so forth are deprecated but are still supported for backwards compatibility.
559
560Fix bug where, when a helper or event handler was called from inside a custom block helper, Template.instance() returned the Template.contentBlock template instead of the actual user-defined template, making it difficult to use Template.instance() for local template state.
561
562Template.instance() now works inside Template.body. #3631
563
564Allow specifying attributes on <body> tags in templates.
565
566Improve performance of rendering large arrays. #3596
567
568Isobuild
569
570Support Npm.require('foo/bar'). #3505 #3526
571
572In package.js files, Npm.require can only require built-in Node modules (and dev bundle modules, though you shouldn't depend on that), not the modules from its own Npm.depends. Previously, such code would work but only on the second time a package.js was executed.
573
574Ignore vim swap files in the public and private directories. #3322
575
576Fix regression in 1.0.2 where packages might not be rebuilt when the compiler version changes.
577
578Meteor Accounts
579
580The accounts-password Accounts.emailTemplates can now specify arbitrary email headers. The from address can now be set separately on the individual templates, and is a function there rather than a static string. #2858 #2854
581
582Add login hooks on the client: Accounts.onLogin and Accounts.onLoginFailure. #3572
583
584Add a unique index to the collection that stores OAuth login configuration to ensure that only one configuration exists per service. #3514
585
586On the server, a new option Accounts.setPassword(user, password, { logout: false }) overrides the default behavior of logging out all logged-in connections for the user. #3846
587
588Webapp
589
590spiderable now supports escaped #! fragments. #2938
591
592Disable appcache on Firefox by default. #3248
593
594Don't overly escape Meteor.settings.public and other parts of __meteor_runtime_config__. #3730
595
596Reload the client program on SIGHUP or Node-specific IPC messages, not SIGUSR2.
597
598meteor command-line tool
599
600Enable tab-completion of global variables in meteor shell. #3227
601
602Improve the stability of meteor shell. #3437 #3595 #3591
603
604meteor login --email no longer takes an ignored argument. #3532
605
606Fix regression in 1.0.2 where meteor run --settings s would ignore errors reading or parsing the settings file. #3757
607
608Fix crash in meteor publish in some cases when the package is inside an app. #3676
609
610Fix crashes in meteor search --show-all and meteor search --maintainer. #3636
611
612Kill PhantomJS processes after meteor --test, and only run the app once. #3205 #3793
613
614Give a better error when Mongo fails to start up due to a full disk. #2378
615
616After killing existing mongod servers, also clear the mongod.lock file.
617
618Stricter validation for package names: they cannot begin with a hyphen, end with a dot, contain two consecutive dots, or start or end with a colon. (No packages on Atmosphere fail this validation.) Additionally, meteor create --package applies the same validation as meteor publish and disallows packages with multiple colons. (Packages with multiple colons like local-test:iron:router are used internally by meteor test-packages so that is not a strict validation rule.)
619
620meteor create --package now no longer creates a directory with the full name of the package, since Windows file systems cannot have colon characters in file paths. Instead, the command now creates a directory named the same as the second part of the package name after the colon (without the username prefix).
621
622Meteor Mobile
623
624Upgrade the Cordova CLI dependency from 3.5.1 to 4.2.0. See the release notes for the 4.x series of the Cordova CLI on Apache Cordova.
625
626Related to the recently discovered attack vectors in Android Cordova apps, Meteor Cordova apps no longer allow access to all domains by default. If your app access external resources over XHR, you need to add them to the whitelist of allowed domains with the newly added App.accessRule method in your mobile-config.js file.
627
628Upgrade Cordova Plugins dependencies in Meteor Core packages:
629
630org.apache.cordova.file: from 1.3.0 to 1.3.3
631org.apache.cordova.file-transfer: from 0.4.4 to 0.5.0
632org.apache.cordova.splashscreen: from 0.3.3 to 1.0.0
633org.apache.cordova.console: from 0.2.10 to 0.2.13
634org.apache.cordova.device: from 0.2.11 to 0.3.0
635org.apache.cordova.statusbar: from 0.1.7 to 0.1.10
636org.apache.cordova.inappbrowser: from 0.5.1 to 0.6.0
637org.apache.cordova.inappbrowser: from 0.5.1 to 0.6.0
638Use the newer ios-sim binary, compiled with Xcode 6 on OS X Mavericks.
639
640Tracker
641
642Use Session.set({k1: v1, k2: v2}) to set multiple values at once.
643Utilities
644
645Provide direct access to all options supported by the request npm module via the new server-only npmRequestOptions option to HTTP.call. #1703
646Other bug fixes and improvements
647
648Many internal refactorings towards supporting Meteor on Windows are in this release.
649
650Remove some packages used internally to support legacy MDG systems (application-configuration, ctl, ctl-helper, follower-livedata, dev-bundle-fetcher, and star-translate).
651
652Provide direct access to some npm modules used by core packages on the NpmModules field of WebAppInternals, MongoInternals, and HTTPInternals.
653
654Upgraded dependencies:
655
656node: 0.10.36 (from 0.10.33)
657Fibers: 1.0.5 (from 1.0.1)
658MongoDB: 2.6.7 (from 2.4.12)
659openssl in mongo: 1.0.2 (from 1.0.1j)
660MongoDB driver: 1.4.32 (from 1.4.1)
661bson: 0.2.18 (from 0.2.7)
662request: 2.53.0 (from 2.47.0)
663Patches contributed by GitHub users 0a-, awatson1978, awwx, bwhitty, christianbundy, d4nyll, dandv, DanielDent, DenisGorbachev, fay-jai, gsuess, hwillson, jakozaur, meonkeys, mitar, netanelgilad, queso, rbabayoff, RobertLowe, romanzolotarev, Siilwyn, and tmeasday.
664
665v.1.0.3.2, 2015-Feb-25
666
667Fix regression in 1.0.3 where the meteor tool could crash when downloading the second build of a given package version; for example, when running meteor deploy on an OSX or 32-bit Linux system for an app containing a binary package. #3761
668v.1.0.3.1, 2015-Jan-20
669
670Rewrite meteor show and meteor search to show package information for local packages and to show if the package is installed for non-local packages. Introduce the --show-all flag, and deprecate the --show-unmigrated and --show-old flags. Introduce the --ejson flag to output an EJSON object.
671
672Support README.md files inmeteor publish. Take in the documentation file in package.js (set to README.md by default) and upload it to the server at publication time. Excerpt the first non-header Markdown section for use in meteor show.
673
674Support updates of package version metadata after that version has been published by running meteor publish --update from the package directory.
675
676Add meteor test-packages --velocity (similar to meteor run --test). #3330
677
678Fix meteor update <packageName> to update even if it's an indirect dependency of your app. #3282
679
680Fix stack trace when a browser tries to use the server like a proxy. #1212
681
682Fix inaccurate session statistics and possible multiple invocation of Connection.onClose callbacks.
683
684Switch CLI tool filesystem calls from synchronous to yielding (pro: more concurrency, more responsive to signals; con: could introduce concurrency bugs)
685
686Don't apply CDN prefix on Cordova. #3278 #3311
687
688Don't try to refresh client app in the runner unless the app actually has the autoupdate package. #3365
689
690Fix custom release banner logic. #3353
691
692Apply HTTP followRedirects option to non-GET requests. #2808
693
694Clean up temporary directories used by package downloads sooner. #3324
695
696If the tool knows about the requested release but doesn't know about the build of its tool for the platform, refresh the catalog rather than failing immediately. #3317
697
698Fix meteor --get-ready to not add packages to your app.
699
700Fix some corner cases in cleaning up app processes in the runner. Drop undocumented --keepalive support. #3315
701
702Fix CSS autoupdate when $ROOT_URL has a non-trivial path. #3111
703
704Save Google OAuth idToken to the User service info object.
705
706Add git info to meteor --version.
707
708Correctly catch a case of illegal Tracker.flush during Tracker.autorun. #3037
709
710Upgraded dependencies:
711
712jquery: 1.11.2 (from 1.11.0)
713Patches by GitHub users DanielDent, DanielDornhardt, PooMaster, Primigenus, Tarang, TomFreudenberg, adnissen, dandv, fay-jai, knownasilya, mquandalle, ogourment, restebanez, rissem, smallhelm and tmeasday.
714
715v1.0.2.1, 2014-Dec-22
716
717Fix crash in file change watcher. #3336
718
719Allow meteor test-packages packages/* even if not all package directories have tests. #3334
720
721Fix typo in meteor shell output. #3326
722
723v1.0.2, 2014-Dec-19
724
725Improvements to the meteor command-line tool
726
727A new command called meteor shell attaches an interactive terminal to an already-running server process, enabling inspection and execution of server-side data and code, with dynamic tab completion of variable names and properties. To see meteor shell in action, type meteor run in an app directory, then (in another terminal) type meteor shell in the same app directory. You do not have to wait for the app to start before typing meteor shell, as it will automatically connect when the server is ready. Note that meteor shell currently works for local development only, and is not yet supported for apps running on remote hosts.
728
729We've done a major internal overhaul of the meteor command-line tool with an eye to correctness, maintainability, and performance. Some details include:
730
731Refresh the package catalog for build commands only when an error occurs that could be fixed by a refresh, not for every build command.
732Never run the constraint solver to select package versions more than once per build.
733Built packages ("isopacks") are now cached inside individual app directories instead of inside their source directories.
734meteor run starts Mongo in parallel with building the application.
735The constraint solver no longer leaves a versions.json file in your packages source directories; when publishing a package that is not inside an app, it will leave a .versions file (with the same format as .meteor/versions) which you should check into source control.
736The constraint solver's model has been simplified so that plugins must use the same version of packages as their surrounding package when built from local source.
737Using meteor debug no longer requires manually continuing the debugger when your app restarts, and it no longer overwrites the symbol _ inside your app.
738
739Output from the command-line tool is now word-wrapped to the width of your terminal.
740
741Remove support for the undocumented earliestCompatibleVersion feature of the package system.
742
743Reduce CPU usage and disk I/O bandwidth by using kernel file-system change notification events where possible. On file systems that do not support these events (NFS, Vagrant Virtualbox shared folders, etc), file changes will only be detected every 5 seconds; to detect changes more often in these cases (but use more CPU), set the METEOR_WATCH_FORCE_POLLING environment variable. #2135
744
745Reduce CPU usage by fixing a check for a parent process in meteor run that was happening constantly instead of every few seconds. #3252
746
747Fix crash when two plugins defined source handlers for the same extension. #3015 #3180
748
749Fix bug (introduced in 0.9.3) where the warning about using experimental versions of packages was printed too often.
750
751Fix bug (introduced in 1.0) where meteor update --patch crashed.
752
753Fix bug (introduced in 0.9.4) where banners about new releases could be printed too many times.
754
755Fix crash when a package version contained a dot-separated pre-release part with both digits and non-digits. #3147
756
757Corporate HTTP proxy support is now implemented using our websocket library's new built-in implementation instead of a custom implementation. #2515
758
759Blaze
760
761Add default behavior for Template.parentData with no arguments. This selects the first parent. #2861
762
763Fix Blaze.remove on a template's view to correctly remove the DOM elements when the template was inserted using Blaze.renderWithData. #3130
764
765Allow curly braces to be escaped in Spacebars. Use the special sequences {{| and {{{| to insert a literal {{ or {{{.
766
767Meteor Accounts
768
769Allow integration with OAuth1 servers that require additional query parameters to be passed with the access token. #2894
770
771Expire a user's password reset and login tokens in all circumstances when their password is changed.
772
773Other bug fixes and improvements
774
775Some packages are no longer released as part of the core release process: amplify, backbone, bootstrap, d3, jquery-history, and jquery-layout. This means that new versions of these packages can be published outside of the full Meteor release cycle.
776
777Require plain objects as the update parameter when doing replacements in server-side collections.
778
779Fix audit-argument-checks spurious failure when an argument is NaN. #2914
780
781Upgraded dependencies
782
783node: 0.10.33 (from 0.10.29)
784source-map-support: 0.2.8 (from 0.2.5)
785semver: 4.1.0 (from 2.2.1)
786request: 2.47.0 (from 2.33.0)
787tar: 1.0.2 (from 1.0.1)
788source-map: 0.1.40 (from 0.1.32)
789sqlite3: 3.0.2 (from 3.0.0)
790phantomjs npm module: 1.9.12 (from 1.8.1-1)
791http-proxy: 1.6.0 (from a fork of 1.0.2)
792esprima: 1.2.2 (from an unreleased 1.1-era commit)
793escope: 1.0.1 (from 1.0.0)
794openssl in mongo: 1.0.1j (from 1.0.1g)
795faye-websocket: 0.8.1 (from using websocket-driver instead)
796MongoDB: 2.4.12 (from 2.4.9)
797Patches by GitHub users andylash, anstarovoyt, benweissmann, chrisbridgett, colllin, dandv, ecwyne, graemian, JamesLefrere, kevinchiu, LyuGGang, matteodem, mitar, mquandalle, musically-ut, ograycode, pcjpcj2, physiocoder, rgoomar, timhaines, trusktr, Urigo, and zol.
798
799v1.0.1, 2014-Dec-09
800
801Fix a security issue in allow/deny rules that could result in data loss. If your app uses allow/deny rules, or uses packages that use allow/deny rules, we recommend that you update immediately.
802v1.0, 2014-Oct-28
803
804New Features
805
806Add the meteor admin get-machine command to make it easier to publish packages with binary dependencies for all architectures. meteor publish no longer publishes builds automatically if your package has binary NPM dependencies.
807
808New localmarket example, highlighting Meteor's support for mobile app development.
809
810Restyle the leaderboard example, and optimize it for both desktop and mobile.
811
812Performance
813
814Reduce unnecessary syncs with the package server, which speeds up startup times for many commands.
815
816Speed up meteor deploy by not bundling unnecessary files and programs.
817
818To make Meteor easier to use on slow or unreliable network connections, increase timeouts for DDP connections that the Meteor tool uses to communicate with the package server. #2777, #2789.
819
820Mobile App Support
821
822Implemented reasonable default behavior for launch screens on mobile apps.
823
824Don't build for Android when only the iOS build is required, and vice versa.
825
826Fix bug that could cause mobile apps to stop being able to receive hot code push updates.
827
828Fix bug where Cordova clients connected to http://example.com instead of https://example.com when https:// was specified in the --mobile-server option. #2880
829
830Fix stack traces when attempting to build or run iOS apps on Linux.
831
832Print a warning when building an app with mobile platforms and outputting the build into the source tree. Outputting a build into the source tree can cause subsequent builds to fail because they will treat the build output as source files.
833
834Exit from meteor run when new Cordova plugins or platforms are added, since we don't support hot code push for new plugins or platforms.
835
836Fix quoting of arguments to Cordova plugins.
837
838The accounts-twitter package now works in Cordova apps in local development. For workarounds for other login providers in local development mode, see https://github.com/meteor/meteor/wiki/OAuth-for-mobile-Meteor-clients.
839
840Packaging
841
842meteor publish-for-arch can publish packages built with different Meteor releases.
843
844Fix default api.versionsFrom field in packages created with meteor create --package.
845
846Fix bug where changes in an app's .meteor/versions file would not cause the app to be rebuilt.
847
848Other bug fixes and improvements
849
850Use TLSv1 in the spiderable package, for compatibility with servers that have disabled SSLv3 in response to the POODLE bug.
851
852Work around the meteor run proxy occasionally running out of sockets.
853
854Fix bug with regular expressions in minimongo. #2817
855
856Add READMEs for several core packages.
857
858Include protocols in URLs printed by meteor deploy.
859
860Improve error message for limited ordered observe. #1643
861
862Fix missing dependency on random in the autoupdate package. #2892
863
864Fix bug where all CSS would be removed from connected clients if a CSS-only change is made between local development server restarts or when deploying with meteor deploy.
865
866Increase height of the Google OAuth popup to the Google-recommended value.
867
868Fix the layout of the OAuth configuration dialog when used with Bootstrap.
869
870Allow build plugins to override the 'bare' option on added source files. #2834
871
872Patches by GitHub users DenisGorbachev, ecwyne, mitar, mquandalle, Primigenus, svda, yauh, and zol.
873
874v0.9.4.1, 2014-Dec-09 (backport)
875
876Fix a security issue in allow/deny rules that could result in data loss. If your app uses allow/deny rules, or uses packages that use allow/deny rules, we recommend that you update immediately. Backport from 1.0.1.
877v0.9.4, 2014-Oct-13
878
879New Features
880
881The new meteor debug command and --debug-port command line option to meteor run allow you to easily use node-inspector to debug your server-side code. Add a debugger statement to your code to create a breakpoint.
882
883Add new a meteor run --test command that runs Velocity tests in your app .
884
885Add new callbacks Accounts.onResetPasswordLink, Accounts.onEnrollmentLink, and Accounts.onEmailVerificationLink that make it easier to build custom user interfaces on top of the accounts system. These callbacks should be registered before Meteor.startup fires, and will be called if the URL matches a link in an email sent by Accounts.resetPassword, etc. See https://docs.meteor.com/#Accounts-onResetPasswordLink.
886
887A new configuration file for mobile apps, <APP>/mobile-config.js. This allows you to set app metadata, icons, splash screens, preferences, and PhoneGap/Cordova plugin settings without needing a cordova_build_override directory. See https://docs.meteor.com/#mobileconfigjs.
888
889API Changes
890
891Rename {{> UI.dynamic}} to {{> Template.dynamic}}, and likewise with UI.contentBlock and UI.elseBlock. The UI namespace is no longer used anywhere except for backwards compatibility.
892
893Deprecate the Template.someTemplate.myHelper = ... syntax in favor of Template.someTemplate.helpers(...). Using the older syntax still works, but prints a deprecation warning to the console.
894
895Package.registerBuildPlugin its associated functions have been added to the public API, cleaned up, and documented. The new function is identical to the earlier _transitional_registerBuildPlugin except for minor backwards-compatible API changes. See https://docs.meteor.com/#Package-registerBuildPlugin
896
897Rename the showdown package to markdown.
898
899Deprecate the amplify, backbone, bootstrap, and d3 integration packages in favor of community alternatives. These packages will no longer be maintained by MDG.
900
901Tool Changes
902
903Improved output from meteor build to make it easier to publish mobile apps to the App Store and Play Store. See the wiki pages for instructions on how to publish your iOS and Android apps.
904
905Packages can now be marked as debug-mode only by adding debugOnly: true to Package.describe. Debug-only packages are not included in the app when it is bundled for production (meteor build or meteor run --production). This allows package authors to build packages specifically for testing and debugging without increasing the size of the resulting app bundle or causing apps to ship with debug functionality built in.
906
907Rework the process for installing mobile development SDKs. There is now a meteor install-sdk command that automatically install what software it can and points to documentation for the parts that require manual installation.
908
909The .meteor/cordova-platforms file has been renamed to .meteor/platforms and now includes the default server and browser platforms. The default platforms can't currently be removed from a project, though this will be possible in the future. The old file will be automatically migrated to the new one when the app is run with Meteor 0.9.4 or above.
910
911The unipackage.json file inside downloaded packages has been renamed to isopack.json and has an improved forwards-compatible format. To maintain backwards compatibility with previous releases, packages will be built with both files.
912
913The local package metadata cache now uses SQLite, which is much faster than the previous implementation. This improves meteor command line tool startup time.
914
915The constraint solver used by the client to find compatible versions of packages is now much faster.
916
917The --port option to meteor run now requires a numeric port (e.g. meteor run --port example.com is no longer valid).
918
919The --mobile-port option meteor run has been reworked. The option is now --mobile-server in meteor run and --server in meteor build. --server is required for meteor build in apps with mobile platforms installed. --mobile-server defaults to an automatically detected IP address on port 3000, and --server requires a hostname but defaults to port 80 if a port is not specified.
920
921Operations that take longer than a few seconds (e.g. downloading packages, installing the Android SDK, etc) now show a progress bar.
922
923Complete support for using an HTTP proxy in the meteor command line tool. Now all DDP connections can work through a proxy. Use the standard http_proxy environment variable to specify your proxy endpoint. #2515
924
925Bug Fixes
926
927Fix behavior of ROOT_URL with path ending in /.
928
929Fix source maps when using a ROOT_URL with a path. #2627
930
931Change the mechanism that the Meteor tool uses to clean up app server processes. The new mechanism is more resilient to slow app bundles and other CPU-intensive tasks. #2536, #2588.
932
933Patches by GitHub users cryptoquick, Gaelan, jperl, meonkeys, mitar, mquandalle, prapicault, pscanf, richguan, rick-golden-healthagen, rissem, rosh93, rzymek, and timoabend
934
935v0.9.3.1, 2014-Sep-30
936
937Don't crash when failing to contact the package server. #2713
938
939Allow more than one dash in package versions. #2715
940
941v0.9.3, 2014-Sep-25
942
943More Package Version Number Flexibility
944
945Packages now support relying on multiple major versions of their dependencies (eg blaze@1.0.0 || 2.0.0). Additionally, you can now call api.versionsFrom(<release>) multiple times, or with an array (eg api.versionsFrom([<release1>, <release2>]). Meteor will interpret this to mean that the package will work with packages from all the listed releases.
946
947Support for "wrapped package" version numbers. There is now a _ field in version numbers. The _ field must be an integer, and versions with the _ are sorted after versions without. This allows using the upstream version number as the Meteor package version number and being able to publish multiple version of the Meteor package (e.g. jquery@1.11.1_2).
948
949Note: packages using the || operator or the _ symbol in their versions or dependencies will be invisible to pre-0.9.3 users. Meteor versions 0.9.2 and before do not understand the new version formats and will not be able to use versions of packages that use the new features.
950
951Other Command-line Tool Improvements
952
953More detailed constraint solver output. Meteor now tells you which constraints prevent upgrading or adding new packages. This will make it much easier to update your app to new versions.
954
955Better handling of pre-release versions (e.g. versions with -). Pre-release packages will now be included in an app if and only if there is no way to meet the app's constraints without using a pre-release package.
956
957Add meteor admin set-unmigrated to allow maintainers to hide pre-0.9.0 packages in meteor search and meteor show. This will not stop users from continuing to use the package, but it helps prevent new users from finding old non-functional packages.
958
959Progress bars for time-intensive operations, like downloading large packages.
960
961Other Changes
962
963Offically support Meteor.wrapAsync (renamed from Meteor._wrapAsync). Additionally, Meteor.wrapAsync now lets you pass an object to bind as this in the wrapped call. See https://docs.meteor.com/#meteor_wrapasync.
964
965The reactive-dict package now allows an optional name argument to enable data persistence during hot code push.
966
967Patches by GitHub users evliu, meonkeys, mitar, mizzao, mquandalle, prapicault, waitingkuo, wulfmeister.
968
969v0.9.2.2, 2014-Sep-17
970
971Fix regression in 0.9.2 that prevented some users from accessing the Meteor development server in their browser. Specifically, 0.9.2 unintentionally changed the development mode server's default bind host to localhost instead of 0.0.0.0. #2596
972v0.9.2.1, 2014-Sep-15
973
974Fix versions of packages that were published with -cordova versions in 0.9.2 (appcache, fastclick, htmljs, logging, mobile-status-bar, routepolicy, webapp-hashing).
975v0.9.2, 2014-Sep-15
976
977This release contains our first support for building mobile apps in Meteor, for both iOS and Android. This support comes via an integration with Apache's Cordova/PhoneGap project.
978
979You can use Cordova/PhoneGap packages in your application or inside a Meteor package to access a device's native functions directly from JavaScript code.
980The meteor add-platform and meteor run commands now let you launch the app in the iOS or Android simulator or run it on an attached hardware device.
981This release extends hot code push to support live updates into installed native apps.
982The meteor bundle command has been renamed to meteor build and now outputs build projects for the mobile version of the targeted app.
983See https://github.com/meteor/meteor/wiki/Meteor-Cordova-Phonegap-integration for more information about how to get started building mobile apps with Meteor.
984Better mobile support for OAuth login: you can now use a redirect-based flow inside UIWebViews, and the existing popup-based flow has been adapted to work in Cordova/PhoneGap apps.
985Bug fixes and minor improvements
986
987Fix sorting on non-trivial keys in Minimongo. #2439
988
989Bug fixes and performance improvements for the package system's constraint solver.
990
991Improved error reporting for misbehaving oplog observe driver. #2033 #2244
992
993Drop deprecated source map linking format used for older versions of Firefox. #2385
994
995Allow Meteor tool to run from a symlink. #2462
996
997Assets added via a plugin are no longer considered source files. #2488
998
999Remove support for long deprecated SERVER_ID environment variable. Use AUTOUPDATE_VERSION instead.
1000
1001Fix bug in reload-safetybelt package that resulted in reload loops in Chrome with cookies disabled.
1002
1003Change the paths for static assets served from packages. The : character is replaced with the _ character in package names so as to allow serving on mobile devices and ease operation on Windows. For example, assets from the abc:bootstrap package are now served at /packages/abc_bootstrap instead of /packages/abc:bootstrap.
1004
1005Also change the paths within a bundled Meteor app to allow for different client architectures (eg mobile). For example, bundle/programs/client is now bundle/programs/web.browser.
1006
1007Patches by GitHub users awwx, mizzao, and mquandalle.
1008
1009v0.9.1.1, 2014-Sep-06
1010
1011Fix backwards compatibility for packages that had weak dependencies on packages renamed in 0.9.1 (ui, deps, livedata). #2521
1012
1013Fix error when using the reactive-dict package without the mongo package.
1014
1015v0.9.1, 2014-Sep-04
1016
1017Organizations in Meteor developer accounts
1018
1019Meteor 0.9.1 ships with organizations support in Meteor developer accounts. Organizations are teams of users that make it easy to collaborate on apps and packages.
1020
1021Create an organization at https://www.meteor.com/account-settings/organizations. Run the meteor authorized command in your terminal to give an organization permissions to your apps. To add an organization as a maintainer of your packages, use the meteor admin maintainers command. You can also publish packages with an organization's name in the package name prefix instead of your own username.
1022
1023One backwards incompatible change for templates
1024
1025Templates can no longer be named "body" or "instance".
1026Backwards compatible Blaze API changes
1027
1028New public and documented APIs:
1029
1030Blaze.toHTMLWithData()
1031Template.currentData()
1032Blaze.getView()
1033Template.parentData() (previously UI._parentData())
1034Template.instance() (previously UI._templateInstance())
1035Template.body (previously UI.body)
1036new Template (previously Template.__create__)
1037Blaze.getData() (previously UI.getElementData, or Blaze.getCurrentData with no arguments)
1038Deprecate the ui package. Instead, use the blaze package. The UI and Blaze symbols are now the same.
1039
1040Deprecate UI.insert. UI.render and UI.renderWithData now render a template and place it in the DOM.
1041
1042Add an underscore to some undocumented Blaze APIs to make them internal. Notably: Blaze._materializeView, Blaze._createView, Blaze._toText, Blaze._destroyView, Blaze._destroyNode, Blaze._withCurrentView, Blaze._DOMBackend, Blaze._TemplateWith
1043
1044Document Views. Views are the machinery powering DOM updates in Blaze.
1045
1046Expose view property on template instances.
1047
1048Backwards compatible renames
1049
1050Package renames
1051livedata -> ddp
1052mongo-livedata -> mongo
1053standard-app-packages -> meteor-platform
1054Symbol renames
1055Meteor.Collection -> Mongo.Collection
1056Meteor.Collection.Cursor -> Mongo.Cursor
1057Meteor.Collection.ObjectID -> Mongo.ObjectID
1058Deps -> Tracker
1059Other
1060
1061Add reactive-var package. Lets you define a single reactive variable, like a single key in Session.
1062
1063Don't throw an exception in Chrome when cookies and local storage are blocked.
1064
1065Bump DDP version to "1". Clients connecting with version "pre1" or "pre2" should still work.
1066
1067Allow query parameters in OAuth1 URLs. #2404
1068
1069Fix meteor list if not all packages on server. Fixes #2468
1070
1071Patch by GitHub user mitar.
1072
1073v0.9.0.1, 2014-Aug-27
1074
1075Fix issues preventing hot code reload from automatically reloading webapps in two cases: when the old app was a pre-0.9.0 app, and when the app used appcache. (In both cases, an explicit reload still worked.)
1076
1077Fix publishing packages containing a plugin with platform-specific code but no platform-specific code in the main package.
1078
1079Fix meteor add package@version when the package was already added with a different version constraint.
1080
1081Improve treatment of pre-release packages (packages with a dash in their version). Guarantee that they will not be chosen by the constraint solver unless explicitly requested. meteor list won't suggest that you update to them.
1082
1083Fix slow spiderable executions.
1084
1085Fix dev-mode client-only restart when client files changed very soon after server restart.
1086
1087Fix stack trace on meteor add constraint solver failure.
1088
1089Fix "access-denied" stack trace when publishing packages.
1090
1091v0.9.0, 2014-Aug-26
1092
1093Meteor 0.9.0 introduces the Meteor Package Server. Incorporating lessons from our community's Meteorite tool, Meteor 0.9.0 allows users to develop and publish Meteor packages to a central repository. The meteor publish command is used to publish packages. Non-core packages can now be added with meteor add, and you can specify version constraints on the packages you use. Binary packages can be published for additional architectures with meteor publish-for-arch, which allows cross-platform deploys and bundling. You can search for packages with meteor search and display information on them with meteor show, or you can use the Atmosphere web interface developed by Percolate Studio at https://atmospherejs.com/
1094
1095See https://docs.meteor.com/#writingpackages and https://docs.meteor.com/#packagejs for more details.
1096
1097Other packaging-related changes:
1098
1099meteor list now lists the packages your app is using, which was formerly the behavior of meteor list --using. To search for packages you are not currently using, use meteor search. The concept of an "internal" package (which did not show up in meteor list) no longer exists.
1100
1101To prepare a bundle created with meteor bundle for execution on a server, you now run npm install with no arguments instead of having to specify a few specific npm modules and their versions explicitly. See the README in the generated bundle for more details.
1102
1103All under_score-style package.js APIs (Package.on_use, api.add_files, etc) have been replaced with camelCase names (Package.onUse, api.addFiles, etc). The old names continue to work for now.
1104
1105There's a new archMatching option to Plugin.registerSourceHandler, which should be used by any plugin whose output is only for the client or only for the server (eg, CSS and HTML templating packages); this allows Meteor to avoid restarting the server when files processed by these plugins change.
1106
1107Other changes:
1108
1109When running your app with the local development server, changes that only affect the client no longer require restarting the server. Changes that only affect CSS no longer require the browser to refresh the page, both in local development and in some production environments. #490
1110
1111When a call to match fails in a method or subscription, log the failure on the server. (This matches the behavior described in our docs)
1112
1113The appcache package now defaults to functioning on all browsers that support the AppCache API, rather than a whitelist of browsers. The main effect of this change is that appcache is now enabled by default on Firefox, because Firefox no longer makes a confusing popup. You can still disable individual browsers with AppCache.config. #2241
1114
1115The forceApprovalPrompt option can now be specified in Accounts.ui.config in addition to Meteor.loginWithGoogle. #2149
1116
1117Don't leak websocket clients in server-to-server DDP in some cases (and fix "Got open from inactive client" error). https://github.com/faye/websocket-driver-node/pull/8
1118
1119Updated OAuth url for login with Meetup.
1120
1121Allow minimongo changed callbacks to mutate their oldDocument argument. #2231
1122
1123Fix upsert called from client with no callback. #2413
1124
1125Avoid a few harmless exceptions in OplogObserveDriver.
1126
1127Refactor observe-sequence package.
1128
1129Fix spiderable race condition.
1130
1131Re-apply our fix of NPM bug https://github.com/npm/npm/issues/3265 which got accidentally reverted upstream.
1132
1133Workaround for a crash in recent Safari versions. https://github.com/meteor/meteor/commit/e897539adb
1134
1135Upgraded dependencies:
1136
1137less: 1.7.4 (from 1.7.1)
1138tar: 1.0.1 (from 0.1.19)
1139fstream: 1.0.2 (from 0.1.25)
1140Patches by GitHub users Cangit, dandv, ImtiazMajeed, MaximDubrovin, mitar, mquandalle, rcy, RichardLitt, thatneat, and twhy.
1141
1142v0.8.3.1, 2014-Dec-09 (backport)
1143
1144Fix a security issue in allow/deny rules that could result in data loss. If your app uses allow/deny rules, or uses packages that use allow/deny rules, we recommend that you update immediately. Backport from 1.0.1.
1145v0.8.3, 2014-Jul-29
1146
1147Blaze
1148
1149Refactor Blaze to simplify internals while preserving the public API. UI.Component has been replaced with Blaze.View.
1150
1151Fix performance issues and memory leaks concerning event handlers.
1152
1153Add UI.remove, which removes a template after UI.render/UI.insert.
1154
1155Add this.autorun to the template instance, which is like Deps.autorun but is automatically stopped when the template is destroyed.
1156
1157Create <a> tags as SVG elements when they have xlink:href attributes. (Previously, <a> tags inside SVGs were never created as SVG elements.) #2178
1158
1159Throw an error in {{foo bar}} if foo is missing or not a function.
1160
1161Cursors returned from template helpers for #each should implement the observeChanges method and don't have to be Minimongo cursors (allowing new custom data stores for Blaze like Miniredis).
1162
1163Remove warnings when {{#each}} iterates over a list of strings, numbers, or other items that contains duplicates. #1980
1164
1165Meteor Accounts
1166
1167Fix regression in 0.8.2 where an exception would be thrown if Meteor.loginWithPassword didn't have a callback. Callbacks to Meteor.loginWithPassword are now optional again. #2255
1168
1169Fix OAuth popup flow in mobile apps that don't support window.opener. #2302
1170
1171Fix "Email already exists" error with MongoDB 2.6. #2238
1172
1173mongo-livedata and minimongo
1174
1175Fix performance issue where a large batch of oplog updates could block the node event loop for long periods. #2299.
1176
1177Fix oplog bug resulting in error message "Buffer inexplicably empty". #2274
1178
1179Fix regression from 0.8.2 that caused collections to appear empty in reactive findOne() or fetch queries that run before a mutator returns. #2275
1180
1181Miscellaneous
1182
1183Stop including code by default that automatically refreshes the page if JavaScript and CSS don't load correctly. While this code is useful in some multi-server deployments, it can cause infinite refresh loops if there are errors on the page. Add the reload-safetybelt package to your app if you want to include this code.
1184
1185On the server, Meteor.startup(c) now calls c immediately if the server has already started up, matching the client behavior. #2239
1186
1187Add support for server-side source maps when debugging with node-inspector.
1188
1189Add WebAppInternals.addStaticJs() for adding static JavaScript code to be served in the app, inline if allowed by browser-policy.
1190
1191Make the tinytest/run method return immediately, so that wait method calls from client tests don't block on server tests completing.
1192
1193Log errors from method invocations on the client if there is no callback provided.
1194
1195Upgraded dependencies:
1196
1197node: 0.10.29 (from 0.10.28)
1198less: 1.7.1 (from 1.6.1)
1199Patches contributed by GitHub users Cangit, cmather, duckspeaker, zol.
1200
1201v0.8.2, 2014-Jun-23
1202
1203Meteor Accounts
1204
1205Switch accounts-password to use bcrypt to store passwords on the server. (Previous versions of Meteor used a protocol called SRP.) Users will be transparently transitioned when they log in. This transition is one-way, so you cannot downgrade a production app once you upgrade to 0.8.2. If you are maintaining an authenticating DDP client:
1206
1207Clients that use the plaintext password login handler (i.e. call the login method with argument { password: <plaintext password> }) will continue to work, but users will not be transitioned from SRP to bcrypt when logging in with this login handler.
1208Clients that use SRP will no longer work. These clients should instead directly call the login method, as in Meteor.loginWithPassword. The argument to the login method can be either:
1209{ password: <plaintext password> }, or
1210{ password: { digest: <password hash>, algorithm: "sha-256" } }, where the password hash is the hex-encoded SHA256 hash of the plaintext password.
1211Show the display name of the currently logged-in user after following an email verification link or a password reset link in accounts-ui.
1212
1213Add a userEmail option to Meteor.loginWithMeteorDeveloperAccount to pre-fill the user's email address in the OAuth popup.
1214
1215Ensure that the user object has updated token information before it is passed to email template functions. #2210
1216
1217Export the function that serves the HTTP response at the end of an OAuth flow as OAuth._endOfLoginResponse. This function can be overridden to make the OAuth popup flow work in certain mobile environments where window.opener is not supported.
1218
1219Remove support for OAuth redirect URLs with a redirect query parameter. This OAuth flow was never documented and never fully worked.
1220
1221Blaze
1222
1223Blaze now tracks individual CSS rules in style attributes and won't overwrite changes to them made by other JavaScript libraries.
1224
1225Add {{> UI.dynamic}} to make it easier to dynamically render a template with a data context.
1226
1227Add UI._templateInstance() for accessing the current template instance from within a block helper.
1228
1229Add UI._parentData(n) for accessing parent data contexts from within a block helper.
1230
1231Add preliminary API for registering hooks to run when Blaze intends to insert, move, or remove DOM elements. For example, you can use these hooks to animate nodes as they are inserted, moved, or removed. To use them, you can set the _uihooks property on a container DOM element. _uihooks is an object that can have any subset of the following three properties:
1232
1233insertElement: function (node, next): called when Blaze intends to insert the DOM element node before the element next
1234moveElement: function (node, next): called when Blaze intends to move the DOM element node before the element next
1235removeElement: function (node): called when Blaze intends to remove the DOM element node
1236
1237Note that when you set one of these functions on a container element, Blaze will not do the actual operation; it's your responsibility to actually insert, move, or remove the node (by calling $(node).remove(), for example).
1238
1239The findAll method on template instances now returns a vanilla array, not a jQuery object. The $ method continues to return a jQuery object. #2039
1240
1241Fix a Blaze memory leak by cleaning up event handlers when a template instance is destroyed. #1997
1242
1243Fix a bug where helpers used by {{#with}} were still re-running when their reactive data sources changed after they had been removed from the DOM.
1244
1245Stop not updating form controls if they're focused. If a field is edited by one user while another user is focused on it, it will just lose its value but maintain its focus. #1965
1246
1247Add _nestInCurrentComputation option to UI.render, fixing a bug in {{#each}} when an item is added inside a computation that subsequently gets invalidated. #2156
1248
1249Fix bug where "=" was not allowed in helper arguments. #2157
1250
1251Fix bug when a template tag immediately follows a Spacebars block comment. #2175
1252
1253Command-line tool
1254
1255Add --directory flag to meteor bundle. Setting this flag outputs a directory rather than a tarball.
1256
1257Speed up updates of NPM modules by upgrading Node to include our fix for https://github.com/npm/npm/issues/3265 instead of passing --force to npm install.
1258
1259Always rebuild on changes to npm-shrinkwrap.json files. #1648
1260
1261Fix uninformative error message when deploying to long hostnames. #1208
1262
1263Increase a buffer size to avoid failing when running MongoDB due to a large number of processes running on the machine, and fix the error message when the failure does occur. #2158
1264
1265Clarify a meteor mongo error message when using the MONGO_URL environment variable. #1256
1266
1267Testing
1268
1269Run server tests from multiple clients serially instead of in parallel. This allows testing features that modify global server state. #2088
1270Security
1271
1272Add Content-Type headers on JavaScript and CSS resources.
1273
1274Add X-Content-Type-Options: nosniff header to browser-policy-content's default policy. If you are using browser-policy-content and you don't want your app to send this header, then call BrowserPolicy.content.allowContentTypeSniffing().
1275
1276Use Meteor.absoluteUrl() to compute the redirect URL in the force-ssl package (instead of the host header).
1277
1278Miscellaneous
1279
1280Allow check to work on the server outside of a Fiber. #2136
1281
1282EJSON custom type conversion functions should not be permitted to yield. #2136
1283
1284The legacy polling observe driver handles errors communicating with MongoDB better and no longer gets "stuck" in some circumstances.
1285
1286Automatically rewind cursors before calls to fetch, forEach, or map. On the client, don't cache the return value of cursor.count() (consistently with the server behavior). cursor.rewind() is now a no-op. #2114
1287
1288Remove an obsolete hack in reporting line numbers for LESS errors. #2216
1289
1290Avoid exceptions when accessing localStorage in certain Internet Explorer configurations. #1291, #1688.
1291
1292Make handle.ready() reactively stop, where handle is a subscription handle.
1293
1294Fix an error message from audit-argument-checks after login.
1295
1296Make the DDP server send an error if the client sends a connect message with a missing or malformed support field. #2125
1297
1298Fix missing jquery dependency in the amplify package. #2113
1299
1300Ban inserting EJSON custom types as documents. #2095
1301
1302Fix incorrect URL rewrites in stylesheets. #2106
1303
1304Upgraded dependencies:
1305
1306node: 0.10.28 (from 0.10.26)
1307uglify-js: 2.4.13 (from 2.4.7)
1308sockjs server: 0.3.9 (from 0.3.8)
1309websocket-driver: 0.3.4 (from 0.3.2)
1310stylus: 0.46.3 (from 0.42.3)
1311Patches contributed by GitHub users awwx, babenzele, Cangit, dandv, ducdigital, emgee3, felixrabe, FredericoC, jbruni, kentonv, mizzao, mquandalle, subhog, tbjers, tmeasday.
1312
1313v0.8.1.3, 2014-May-22
1314
1315Fix a security issue in the spiderable package. spiderable now uses the ROOT_URL environment variable instead of the Host header to determine which page to snapshot.
1316
1317Fix hardcoded Twitter URL in oauth1 package. This fixes a regression in 0.8.0.1 that broke Atmosphere packages that do OAuth1 logins. #2154.
1318
1319Add credentialSecret argument to Google.retrieveCredential, which was forgotten in a previous release.
1320
1321Remove nonexistent -a and -r aliases for --add and --remove in meteor help authorized. #2155
1322
1323Add missing underscore dependency in the oauth-encryption package. #2165
1324
1325Work around IE8 bug that caused some apps to fail to render when minified. #2037.
1326
1327v0.8.1.2, 2014-May-12
1328
1329Fix memory leak (introduced in 0.8.1) by making sure to unregister sessions at the server when they are closed due to heartbeat timeout.
1330
1331Add credentialSecret argument to Google.retrieveCredential, Facebook.retrieveCredential, etc., which is needed to use them as of 0.8.1. #2118
1332
1333Fix 0.8.1 regression that broke apps using a ROOT_URL with a path prefix. #2109
1334
1335v0.8.1.1, 2014-May-01
1336
1337Fix 0.8.1 regression preventing clients from specifying _id on insert. #2097
1338
1339Fix handling of malformed URLs when merging CSS files. #2103, #2093
1340
1341Loosen the checks on the options argument to Collection.find to allow undefined values.
1342
1343v0.8.1, 2014-Apr-30
1344
1345Meteor Accounts
1346
1347Fix a security flaw in OAuth1 and OAuth2 implementations. If you are using any OAuth accounts packages (such as accounts-google or accounts-twitter), we recommend that you update immediately and log out your users' current sessions with the following MongoDB command:
1348
1349$ db.users.update({}, { $set: { 'services.resume.loginTokens': [] } }, { multi: true });
1350
1351OAuth redirect URLs are now required to be on the same origin as your app.
1352
1353Log out a user's other sessions when they change their password.
1354
1355Store pending OAuth login results in the database instead of in-memory, so that an OAuth flow succeeds even if different requests go to different server processes.
1356
1357When validateLoginAttempt callbacks return false, don't override a more specific error message.
1358
1359Add Random.secret() for generating security-critical secrets like login tokens.
1360
1361Meteor.logoutOtherClients now calls the user callback when other login tokens have actually been removed from the database, not when they have been marked for eventual removal. #1915
1362
1363Rename Oauth to OAuth. Oauth is now an alias for backwards compatibility.
1364
1365Add oauth-encryption package for encrypting sensitive account credentials in the database.
1366
1367A validate login hook can now override the exception thrown from beginPasswordExchange like it can for other login methods.
1368
1369Remove an expensive observe over all users in the accounts-base package.
1370
1371Blaze
1372
1373Disallow javascript: URLs in URL attribute values by default, to help prevent cross-site scripting bugs. Call UI._allowJavascriptUrls() to allow them.
1374
1375Fix UI.toHTML on templates containing {{#with}}.
1376
1377Fix {{#with}} over a data context that is mutated. #2046
1378
1379Clean up autoruns when calling UI.toHTML.
1380
1381Properly clean up event listeners when removing templates.
1382
1383Add support for {{!-- block comments --}} in Spacebars. Block comments may contain }}, so they are more useful than {{! normal comments}} for commenting out sections of Spacebars templates.
1384
1385Don't dynamically insert <tbody> tags in reactive tables
1386
1387When handling a custom jQuery event, additional arguments are no longer lost -- they now come after the template instance argument. #1988
1388
1389DDP and MongoDB
1390
1391Extend latency compensation to support an arbitrary sequence of inserts in methods. Previously, documents created inside a method stub on the client would eventually be replaced by new documents from the server, causing the screen to flicker. Calling insert inside a method body now generates the same ID on the client (inside the method stub) and on the server. A sequence of inserts also generates the same sequence of IDs. Code that wants a random stream that is consistent between method stub and real method execution can get one with DDP.randomStream. https://trello.com/c/moiiS2rP/57-pattern-for-creating-multiple-database-records-from-a-method
1392
1393The document passed to the insert callback of allow and deny now only has a _id field if the client explicitly specified one; this allows you to use allow/deny rules to prevent clients from specifying their own _id. As an exception, allow/deny rules with a transform always have an _id.
1394
1395DDP now has an implementation of bidirectional heartbeats which is consistent across SockJS and websocket transports. This enables connection keepalive and allows servers and clients to more consistently and efficiently detect disconnection.
1396
1397The DDP protocol version number has been incremented to "pre2" (adding randomSeed and heartbeats).
1398
1399The oplog observe driver handles errors communicating with MongoDB better and knows to re-poll all queries after a MongoDB failover.
1400
1401Fix bugs involving mutating DDP method arguments.
1402
1403meteor command-line tool
1404
1405Move boilerplate HTML from tools to webapp. Change internal Webapp.addHtmlAttributeHook API.
1406
1407Add meteor list-sites command for listing the sites that you have deployed to meteor.com with your Meteor developer account.
1408
1409Third-party template languages can request that their generated source loads before other JavaScript files, just like *.html files, by passing the isTemplate option to Plugin.registerSourceHandler.
1410
1411You can specify a particular interface for the dev mode runner to bind to with meteor -p host:port.
1412
1413Don't include proprietary tar tags in bundle tarballs.
1414
1415Convert relative URLs to absolute URLs when merging CSS files.
1416
1417Upgraded dependencies
1418
1419Node.js from 0.10.25 to 0.10.26.
1420MongoDB driver from 1.3.19 to 1.4.1
1421stylus: 0.42.3 (from 0.42.2)
1422showdown: 0.3.1
1423css-parse: an unreleased version (from 1.7.0)
1424css-stringify: an unreleased version (from 1.4.1)
1425Patches contributed by GitHub users aldeed, apendua, arbesfeld, awwx, dandv, davegonzalez, emgee3, justinsb, mquandalle, Neftedollar, Pent, sdarnell, and timhaines.
1426
1427v0.8.0.1, 2014-Apr-21
1428
1429Fix security flaw in OAuth1 implementation. Clients can no longer choose the callback_url for OAuth1 logins.
1430v0.8.0, 2014-Mar-27
1431
1432Meteor 0.8.0 introduces Blaze, a total rewrite of our live templating engine, replacing Spark. Advantages of Blaze include:
1433
1434Better interoperability with jQuery plugins and other techniques which directly manipulate the DOM
1435More fine-grained updates: only the specific elements or attributes that change are touched rather than the entire template
1436A fully documented templating language
1437No need for the confusing {{#constant}}, {{#isolate}}, and preserve directives
1438Uses standard jQuery delegation (.on) instead of our custom implementation
1439Blaze supports live SVG templates that work just like HTML templates
1440See the Using Blaze wiki page for full details on upgrading your app to 0.8.0. This includes:
1441
1442The Template.foo.rendered callback is now only called once when the template is rendered, rather than repeatedly as it is "re-rendered", because templates now directly update changed data instead of fully re-rendering.
1443
1444The accounts-ui login buttons are now invoked as a {{> loginButtons}} rather than as {{loginButtons}}.
1445
1446Previous versions of Meteor used a heavily modified version of the Handlebars templating language. In 0.8.0, we've given it its own name: Spacebars! Spacebars has an explicit specification instead of being defined as a series of changes to Handlebars. There are some incompatibilities with our previous Handlebars fork, such as a different way of specifying dynamic element attributes and a new way of defining custom block helpers.
1447
1448Your template files must consist of well-formed HTML. Invalid HTML is now a compilation failure. (There is a current limitation in our HTML parser such that it does not support omitting end tags on elements such as <P> and <LI>.)
1449
1450Template.foo is no longer a function. It is instead a "component". Components render to an intermediate representation of an HTML tree, not a string, so there is no longer an easy way to render a component to a static HTML string.
1451
1452Meteor.render and Spark.render have been removed. Use UI.render and UI.insert instead.
1453
1454The <body> tag now defines a template just like the <template> tag, which can have helpers and event handlers. Define them directly on the object UI.body.
1455
1456Previous versions of Meteor shipped with a synthesized tap event, implementing a zero-delay click event on mobile browsers. Unfortunately, this event never worked very well. We're eliminating it. Instead, use one of the excellent third party solutions.
1457
1458The madewith package (which supported adding a badge to your website displaying its score from http://madewith.meteor.com/) has been removed, as it is not compatible with the new version of that site.
1459
1460The internal spark, liverange, universal-events, and domutils packages have been removed.
1461
1462The Handlebars namespace has been deprecated. Handlebars.SafeString is now Spacebars.SafeString, and Handlebars.registerHelper is now UI.registerHelper.
1463
1464Patches contributed by GitHub users cmather and mart-jansink.
1465
1466v0.7.2.3, 2014-Dec-09 (backport)
1467
1468Fix a security issue in allow/deny rules that could result in data loss. If your app uses allow/deny rules, or uses packages that use allow/deny rules, we recommend that you update immediately. Backport from 1.0.1.
1469v0.7.2.2, 2014-Apr-21 (backport)
1470
1471Fix a security flaw in OAuth1 and OAuth2 implementations. Backport from 0.8.1; see its entry for recommended actions to take.
1472v0.7.2.1, 2014-Apr-30 (backport)
1473
1474Fix security flaw in OAuth1 implementation. Clients can no longer choose the callback_url for OAuth1 logins. Backport from 0.8.0.1.
1475v0.7.2, 2014-Mar-18
1476
1477Support oplog tailing on queries with the limit option. All queries except those containing $near or $where selectors or the skip option can now be used with the oplog driver.
1478
1479Add hooks to login process: Accounts.onLogin, Accounts.onLoginFailure, and Accounts.validateLoginAttempt. These functions allow for rate limiting login attempts, logging an audit trail, account lockout flags, and more. See: http://docs.meteor.com/#accounts_validateloginattempt #1815
1480
1481Change the Accounts.registerLoginHandler API for custom login methods. Login handlers now require a name and no longer have to deal with generating resume tokens. See https://github.com/meteor/meteor/blob/devel/packages/accounts-base/accounts_server.js for details. OAuth based login handlers using the Oauth.registerService packages are not affected.
1482
1483Add support for HTML email in Accounts.emailTemplates. #1785
1484
1485minimongo: Support {a: {$elemMatch: {x: 1, $or: [{a: 1}, {b: 1}]}}} #1875
1486
1487minimongo: Support {a: {$regex: '', $options: 'i'}} #1874
1488
1489minimongo: Fix sort implementation with multiple sort fields which each look inside an array. eg, ensure that with sort key {'a.x': 1, 'a.y': 1}, the document {a: [{x: 0, y: 4}]} sorts before {a: [{x: 0, y: 5}, {x: 1, y: 3}]}, because the 3 should not be used as a tie-breaker because it is not "next to" the tied 0s.
1490
1491minimongo: Fix sort implementation when selector and sort key share a field, that field matches an array in the document, and only some values of the array match the selector. eg, ensure that with sort key {a: 1} and selector {a: {$gt: 3}}, the document {a: [4, 6]} sorts before {a: [1, 5]}, because the 1 should not be used as a sort key because it does not match the selector. (We only approximate the MongoDB behavior here by only supporting relatively selectors.)
1492
1493Use faye-websocket (0.7.2) npm module instead of websocket (1.0.8) for server-to-server DDP.
1494
1495Update Google OAuth package to use new profile and email scopes instead of deprecated URL-based scopes. #1887
1496
1497Add _throwFirstError option to Deps.flush.
1498
1499Make facts package data available on the server as Facts._factsByPackage.
1500
1501Fix issue where LESS compilation error could crash the meteor run process. #1877
1502
1503Fix crash caused by empty HTTP host header in meteor run development server. #1871
1504
1505Fix hot code reload in private browsing mode in Safari.
1506
1507Fix appcache size calculation to avoid erronious warnings. #1847
1508
1509Remove unused Deps._makeNonReactive wrapper function. Call Deps.nonreactive directly instead.
1510
1511Avoid setting the oplogReplay on non-oplog collections. Doing so caused mongod to crash.
1512
1513Add startup message to test-in-console to ease automation. #1884
1514
1515Upgraded dependencies
1516
1517amplify: 1.1.2 (from 1.1.0)
1518Patches contributed by GitHub users awwx, dandv, queso, rgould, timhaines, zol
1519
1520v0.7.1.2, 2014-Feb-27
1521
1522Fix bug in tool error handling that caused meteor to crash on Mac OSX when no computer name is set.
1523
1524Work around a bug that caused MongoDB to fail an assertion when using tailable cursors on non-oplog collections.
1525
1526v0.7.1.1, 2014-Feb-24
1527
1528Integrate with Meteor developer accounts, a new way of managing your meteor.com deployed sites. When you use meteor deploy, you will be prompted to create a developer account.
1529
1530Once you've created a developer account, you can log in and out from the command line with meteor login and meteor logout.
1531You can claim legacy sites with meteor claim. This command will prompt you for your site password if you are claiming a password-protected site; after claiming it, you will not need to enter the site password again.
1532You can add or remove authorized users, and view the list of authorized users, for a site with meteor authorized.
1533You can view your current username with meteor whoami.
1534This release also includes the accounts-meteor-developer package for building Meteor apps that allow users to log in with their own developer accounts.
1535Improve the oplog tailing implementation for getting real-time database updates from MongoDB.
1536
1537Add support for all operators except $where and $near. Limit and skip are not supported yet.
1538Add optimizations to avoid needless data fetches from MongoDB.
1539Fix an error ("Cannot call method 'has' of null") in an oplog callback. #1767
1540Add and improve support for minimongo operators.
1541
1542Support $comment.
1543Support obj name in $where.
1544$regex matches actual regexps properly.
1545Improve support for $nin, $ne, $not.
1546Support using { $in: [/foo/, /bar/] }. #1707
1547Support {$exists: false}.
1548Improve type-checking for selectors.
1549Support {x: {$elemMatch: {$gt: 5}}}.
1550Match Mongo's behavior better when there are arrays in the document.
1551Support $near with sort.
1552Implement updates with { $set: { 'a.$.b': 5 } }.
1553Support {$type: 4} queries.
1554Optimize remove({}) when observers are paused.
1555Make update-by-id constant time.
1556Allow {$set: {'x._id': 1}}. #1794
1557Upgraded dependencies
1558
1559node: 0.10.25 (from 0.10.22). The workaround for specific Node versions from 0.7.0 is now removed; 0.10.25+ is supported.
1560jquery: 1.11.0 (from 1.8.2). See http://jquery.com/upgrade-guide/1.9/ for upgrade instructions.
1561jquery-waypoints: 2.0.4 (from 1.1.7). Contains backwards-incompatible changes.
1562source-map: 0.3.2 (from 0.3.30) #1782
1563websocket-driver: 0.3.2 (from 0.3.1)
1564http-proxy: 1.0.2 (from a pre-release fork of 1.0)
1565semver: 2.2.1 (from 2.1.0)
1566request: 2.33.0 (from 2.27.0)
1567fstream: 0.1.25 (from 0.1.24)
1568tar: 0.1.19 (from 0.1.18)
1569eachline: a fork of 2.4.0 (from 2.3.3)
1570source-map: 0.1.31 (from 0.1.30)
1571source-map-support: 0.2.5 (from 0.2.3)
1572mongo: 2.4.9 (from 2.4.8)
1573openssl in mongo: 1.0.1f (from 1.0.1e)
1574kexec: 0.2.0 (from 0.1.1)
1575less: 1.6.1 (from 1.3.3)
1576stylus: 0.42.2 (from 0.37.0)
1577nib: 1.0.2 (from 1.0.0)
1578coffeescript: 1.7.1 (from 1.6.3)
1579CSS preprocessing and sourcemaps:
1580
1581Add sourcemap support for CSS stylesheet preprocessors. Use sourcemaps for stylesheets compiled with LESS.
1582Improve CSS minification to deal with @import statements correctly.
1583Lint CSS files for invalid @ directives.
1584Change the recommended suffix for imported LESS files from .lessimport to .import.less. Add .import.styl to allow stylus imports. .lessimport continues to work but is deprecated.
1585Add clientAddress and httpHeaders to this.connection in method calls and publish functions.
1586
1587Hash login tokens before storing them in the database. Legacy unhashed tokens are upgraded to hashed tokens in the database as they are used in login requests.
1588
1589Change default accounts-ui styling and add more CSS classes.
1590
1591Refactor command-line tool. Add test harness and better tests. Run meteor self-test --help for info on running the tools test suite.
1592
1593Speed up application re-build in development mode by re-using file hash computation between file change watching code and application build code..
1594
1595Fix issues with documents containing a key named length with a numeric value. Underscore treated these as arrays instead of objects, leading to exceptions when . Patch Underscore to not treat plain objects (x.constructor === Object) with numeric length fields as arrays. #594 #1737
1596
1597Deprecate Accounts.loginServiceConfiguration in favor of ServiceConfiguration.configurations, exported by the service-configuration package. Accounts.loginServiceConfiguration is maintained for backwards-compatibility, but it is defined in a Meteor.startup block and so cannot be used from top-level code.
1598
1599Cursors with a field specifier containing {_id: 0} can no longer be used with observeChanges or observe. This includes the implicit calls to these functions that are done when returning a cursor from a publish function or using {{#each}}.
1600
1601Transform functions must return objects and may not change the _id field, though they may leave it out.
1602
1603Remove broken IE7 support from the localstorage package. Meteor accounts logins no longer persist in IE7.
1604
1605Fix the localstorage package when used with Safari in private browsing mode. This fixes a problem with login token storage and account login. #1291
1606
1607Types added with EJSON.addType now have default clone and equals implementations. Users may still specify clone or equals functions to override the default behavior. #1745
1608
1609Add frame-src to browser-policy-content and account for cross-browser CSP disparities.
1610
1611Deprecate Oauth.initiateLogin in favor of Oauth.showPopup.
1612
1613Add WebApp.rawConnectHandlers for adding connect handlers that run before any other Meteor handlers, except connect.compress(). Raw connect handlers see the URL's full path (even if ROOT_URL contains a non-empty path) and they run before static assets are served.
1614
1615Add Accounts.connection to allow using Meteor accounts packages with a non-default DDP connection.
1616
1617Detect and reload if minified CSS files fail to load at startup. This prevents the application from running unstyled if the page load occurs while the server is switching versions.
1618
1619Allow Npm.depends to specify any http or https URL containing a full 40-hex-digit SHA. #1686
1620
1621Add retry package for connection retry with exponential backoff.
1622
1623Pass update and remove return values correctly when using collections validated with allow and deny rules. #1759
1624
1625If you're using Deps on the server, computations and invalidation functions are not allowed to yield. Throw an error instead of behaving unpredictably.
1626
1627Fix namespacing in coffeescript files added to a package with the bare: true option. #1668
1628
1629Fix races when calling login and/or logoutOtherClients from multiple tabs. #1616
1630
1631Include oauth_verifier as a header rather than a parameter in the oauth1 package. #1825
1632
1633Fix force-ssl to allow local development with meteor run in IPv6 environments. #1751`
1634
1635Allow cursors on named local collections to be returned from a publish function in an array. #1820
1636
1637Fix build failure caused by a directory in programs/ without a package.js file.
1638
1639Do a better job of handling shrinkwrap files when an npm module depends on something that isn't a semver. #1684
1640
1641Fix failures updating npm dependencies when a node_modules directory exists above the project directory. #1761
1642
1643Preserve permissions (eg, executable bit) on npm files. #1808
1644
1645SockJS tweak to support relative base URLs.
1646
1647Don't leak sockets on error in dev-mode proxy.
1648
1649Clone arguments to added and changed methods in publish functions. This allows callers to reuse objects and prevents already published data from changing after the fact. #1750
1650
1651Ensure springboarding to a different meteor tools version always uses exec to run the old version. This simplifies process management for wrapper scripts.
1652
1653Patches contributed by GitHub users DenisGorbachev, EOT, OyoKooN, awwx, dandv, icellan, jfhamlin, marcandre, michaelbishop, mitar, mizzao, mquandalle, paulswartz, rdickert, rzymek, timhaines, and yeputons.
1654
1655v0.7.0.1, 2013-Dec-20
1656
1657Two fixes to meteor run Mongo startup bugs that could lead to hangs with the message "Initializing mongo database... this may take a moment.". #1696
1658
1659Apply the Node patch to 0.10.24 as well (see the 0.7.0 section for details).
1660
1661Fix gratuitous IE7 incompatibility. #1690
1662
1663v0.7.0, 2013-Dec-17
1664
1665This version of Meteor contains a patch for a bug in Node 0.10 which most commonly affects websockets. The patch is against Node version 0.10.22 and 0.10.23. We strongly recommend using one of these precise versions of Node in production so that the patch will be applied. If you use a newer version of Node with this version of Meteor, Meteor will not apply the patch and will instead disable websockets.
1666
1667Rework how Meteor gets realtime database updates from MongoDB. Meteor now reads the MongoDB "oplog" -- a special collection that records all the write operations as they are applied to your database. This means changes to the database are instantly noticed and reflected in Meteor, whether they originated from Meteor or from an external database client. Oplog tailing is automatically enabled in development mode with meteor run, and can be enabled in production with the MONGO_OPLOG_URL environment variable. Currently the only supported selectors are equality checks; $-operators, limit and skip queries fall back to the original poll-and-diff algorithm. See https://github.com/meteor/meteor/wiki/Oplog-Observe-Driver for details.
1668
1669Add Meteor.onConnection and add this.connection to method invocations and publish functions. These can be used to store data associated with individual clients between subscriptions and method calls. See http://docs.meteor.com/#meteor_onconnection for details. #1611
1670
1671Bundler failures cause non-zero exit code in meteor run. #1515
1672
1673Fix error when publish function callbacks are called during session shutdown.
1674
1675Rework hot code push. The new autoupdate package drives automatic reloads on update using standard DDP messages instead of a hardcoded message at DDP startup. Now the hot code push only triggers when client code changes; server-only code changes will not cause the page to reload.
1676
1677New facts package publishes internal statistics about Meteor.
1678
1679Add an explicit check that publish functions return a cursor, an array of cursors, or a falsey value. This is a safety check to to prevent users from accidentally returning Collection.findOne() or some other value and expecting it to be published.
1680
1681Implement $each, $sort, and $slice options for minimongo's $push modifier. #1492
1682
1683Introduce --raw-logs option to meteor run to disable log coloring and timestamps.
1684
1685Add WebAppInternals.setBundledJsCssPrefix() to control where the client loads bundled JavaScript and CSS files. This allows serving files from a CDN to decrease page load times and reduce server load.
1686
1687Attempt to exit cleanly on SIGHUP. Stop accepting incoming connections, kill DDP connections, and finish all outstanding requests for static assets.
1688
1689In the HTTP server, only keep sockets with no active HTTP requests alive for 5 seconds.
1690
1691Fix handling of fields option in minimongo when only _id is present. #1651
1692
1693Fix issue where setting process.env.MAIL_URL in app code would not alter where mail was sent. This was a regression in 0.6.6 from 0.6.5. #1649
1694
1695Use stderr instead of stdout (for easier automation in shell scripts) when prompting for passwords and when downloading the dev bundle. #1600
1696
1697Ensure more downtime during file watching. #1506
1698
1699Fix meteor run with settings files containing non-ASCII characters. #1497
1700
1701Support EJSON.clone for Meteor.Error. As a result, they are properly stringified in DDP even if thrown through a Future. #1482
1702
1703Fix passing transform: null option to collection.allow() to disable transformation in validators. #1659
1704
1705Fix livedata error on this.removed during session shutdown. #1540 #1553
1706
1707Fix incompatibility with Phusion Passenger by removing an unused line. #1613
1708
1709Ensure install script creates /usr/local on machines where it does not exist (eg. fresh install of OSX Mavericks).
1710
1711Set x-forwarded-* headers in meteor run.
1712
1713Clean up package dirs containing only ".build".
1714
1715Check for matching hostname before doing end-of-oauth redirect.
1716
1717Only count files that actually go in the cache towards the appcache size check. #1653.
1718
1719Increase the maximum size spiderable will return for a page from 200kB to 5MB.
1720
1721Upgraded dependencies:
1722
1723SockJS server from 0.3.7 to 0.3.8, including new faye-websocket module.
1724Node from 0.10.21 to 0.10.22
1725MongoDB from 2.4.6 to 2.4.8
1726clean-css from 1.1.2 to 2.0.2
1727uglify-js from a fork of 2.4.0 to 2.4.7
1728handlebars npm module no longer available outside of handlebars package
1729Patches contributed by GitHub users AlexeyMK, awwx, dandv, DenisGorbachev, emgee3, FooBarWidget, mitar, mcbain, rzymek, and sdarnell.
1730
1731v0.6.6.3, 2013-Nov-04
1732
1733Fix error when publish function callbacks are called during session shutdown. #1540 #1553
1734
1735Improve meteor run CPU usage in projects with many directories. #1506
1736
1737v0.6.6.2, 2013-Oct-21
1738
1739Upgrade Node from 0.10.20 to 0.10.21 (security update).
1740v0.6.6.1, 2013-Oct-12
1741
1742Fix file watching on OSX. Work around Node issue #6251 by not using fs.watch. #1483
1743v0.6.6, 2013-Oct-10
1744
1745Security
1746
1747Add browser-policy package for configuring and sending Content-Security-Policy and X-Frame-Options HTTP headers. See the docs for more.
1748
1749Use cryptographically strong pseudorandom number generators when available.
1750
1751MongoDB
1752
1753Add upsert support. Collection.update now supports the {upsert: true} option. Additionally, add a Collection.upsert method which returns the newly inserted object id if applicable.
1754
1755update and remove now return the number of documents affected. #1046
1756
1757$near operator for 2d and 2dsphere indices.
1758
1759The fields option to the collection methods find and findOne now works on the client as well. (Operators such as $elemMatch and $ are not yet supported in fields projections.) #1287
1760
1761Pass an index and the cursor itself to the callbacks in cursor.forEach and cursor.map, just like the corresponding Array methods. #63
1762
1763Support c.find(query, {limit: N}).count() on the client. #654
1764
1765Improve behavior of $ne, $nin, and $not selectors with objects containing arrays. #1451
1766
1767Fix various bugs if you had two documents with the same _id field in String and ObjectID form.
1768
1769Accounts
1770
1771[Behavior Change] Expire login tokens periodically. Defaults to 90 days. Use Accounts.config({loginExpirationInDays: null}) to disable token expiration.
1772
1773[Behavior Change] Write dates generated by Meteor Accounts to Mongo as Date instead of number; existing data can be converted by passing it through new Date(). #1228
1774
1775Log out and close connections for users if they are deleted from the database.
1776
1777Add Meteor.logoutOtherClients() for logging out other connections logged in as the current user.
1778
1779restrictCreationByEmailDomain option in Accounts.config to restrict new users to emails of specific domain (eg. only users with @meteor.com emails) or a custom validator. #1332
1780
1781Support OAuth1 services that require request token secrets as well as authentication token secrets. #1253
1782
1783Warn if Accounts.config is only called on the client. #828
1784
1785Fix bug where callbacks to login functions could be called multiple times when the client reconnects.
1786
1787DDP
1788
1789Fix infinite loop if a client disconnects while a long yielding method is running.
1790
1791Unfinished code to support DDP session resumption has been removed. Meteor servers now stop processing messages from clients and reclaim memory associated with them as soon as they are disconnected instead of a few minutes later.
1792
1793Tools
1794
1795The pre-0.6.5 Package.register_extension API has been removed. Use Package._transitional_registerBuildPlugin instead, which was introduced in 0.6.5. (A bug prevented the 0.6.5 reimplementation of register_extension from working properly anyway.)
1796
1797Support using an HTTP proxy in the meteor command line tool. This allows the update, deploy, logs, and mongo commands to work behind a proxy. Use the standard http_proxy environment variable to specify your proxy endpoint. #429, #689, #1338
1798
1799Build Linux binaries on an older Linux machine. Meteor now supports running on Linux machines with glibc 2.9 or newer (Ubuntu 10.04+, RHEL and CentOS 6+, Fedora 10+, Debian 6+). Improve error message when running on Linux with unsupported glibc, and include Mongo stderr if it fails to start.
1800
1801Install NPM modules with --force to avoid corrupted local caches.
1802
1803Rebuild NPM modules in packages when upgrading to a version of Meteor that uses a different version of Node.
1804
1805Disable the Mongo http interface. This lets you run meteor on two ports differing by 1000 at the same time.
1806
1807Misc
1808
1809[Known issue] Breaks support for pre-release OSX 10.9 'Mavericks'. Will be addressed shortly. See issues: https://github.com/joyent/node/issues/6251 https://github.com/joyent/node/issues/6296
1810
1811EJSON.stringify now takes options:
1812
1813canonical causes objects keys to be stringified in sorted order
1814indent allows formatting control over the EJSON stringification
1815EJSON now supports Infinity, -Infinity and NaN.
1816
1817Check that the argument to EJSON.parse is a string. #1401
1818
1819Better error from functions that use Meteor._wrapAsync (eg collection write methods and HTTP methods) and in DDP server message processing. #1387
1820
1821Support appcache on Chrome for iOS.
1822
1823Support literate CoffeeScript files with the extension .coffee.md (in addition to the already-supported .litcoffee extension). #1407
1824
1825Make madewith package work again (broken in 0.6.5). #1448
1826
1827Better error when passing a string to {{#each}}. #722
1828
1829Add support for JSESSIONID cookies for sticky sessions. Set the USE_JSESSIONID environment variable to enable placing a JSESSIONID cookie on sockjs requests.
1830
1831Simplify the static analysis used to detect package-scope variables.
1832
1833Upgraded dependencies:
1834
1835Node from 0.8.24 to 0.10.20
1836MongoDB from 2.4.4 to 2.4.6
1837MongoDB driver from 1.3.17 to 1.3.19
1838http-proxy from 0.10.1 to a pre-release of 1.0.0
1839stylus from 0.30.1 to 0.37.0
1840nib from 0.8.2 to 1.0.0
1841optimist from 0.3.5 to 0.6.0
1842semver from 1.1.0 to 2.1.0
1843request from 2.12.0 to 2.27.0
1844keypress from 0.1.0 to 0.2.1
1845underscore from 1.5.1 to 1.5.2
1846fstream from 0.1.21 to 0.1.24
1847tar from 0.1.14 to 0.1.18
1848source-map from 0.1.26 to 0.1.30
1849source-map-support from a fork of 0.1.8 to 0.2.3
1850escope from a fork of 0.0.15 to 1.0.0
1851estraverse from 1.1.2-1 to 1.3.1
1852simplesmtp from 0.1.25 to 0.3.10
1853stream-buffers from 0.2.3 to 0.2.5
1854websocket from 1.0.7 to 1.0.8
1855cli-color from 0.2.2 to 0.2.3
1856clean-css from 1.0.11 to 1.1.2
1857UglifyJS2 from a fork of 2.3.6 to a different fork of 2.4.0
1858connect from 2.7.10 to 2.9.0
1859send from 0.1.0 to 0.1.4
1860useragent from 2.0.1 to 2.0.7
1861replaced byline with eachline 2.3.3
1862Patches contributed by GitHub users ansman, awwx, codeinthehole, jacott, Maxhodges, meawoppl, mitar, mizzao, mquandalle, nathan-muir, RobertLowe, ryw, sdarnell, and timhaines.
1863
1864v0.6.5.3, 2014-Dec-09 (backport)
1865
1866Fix a security issue in allow/deny rules that could result in data loss. If your app uses allow/deny rules, or uses packages that use allow/deny rules, we recommend that you update immediately. Backport from 1.0.1.
1867v0.6.5.2, 2013-Oct-21
1868
1869Upgrade Node from 0.8.24 to 0.8.26 (security patch)
1870v0.6.5.1, 2013-Aug-28
1871
1872Fix syntax errors on lines that end with a backslash. #1326
1873
1874Fix serving static files with special characters in their name. #1339
1875
1876Upgrade esprima JavaScript parser to fix bug parsing complex regexps.
1877
1878Export Spiderable from spiderable package to allow users to set Spiderable.userAgentRegExps to control what user agents are treated as spiders.
1879
1880Add EJSON to standard-app-packages. #1343
1881
1882Fix bug in d3 tab character parsing.
1883
1884Fix regression when using Mongo ObjectIDs in Spark templates.
1885
1886v0.6.5, 2013-Aug-14
1887
1888New package system with package compiler and linker:
1889
1890Each package now has it own namespace for variable declarations. Global variables used in a package are limited to package scope.
1891
1892Packages must explicitly declare which symbols they export with api.export in package.js.
1893
1894Apps and packages only see the exported symbols from packages they explicitly use. For example, if your app uses package A which in turn depends on package B, only package A's symbols will be available in the app.
1895
1896Package names can only contain alphanumeric characters, dashes, and dots. Packages with spaces and underscores must be renamed.
1897
1898Remove hardcoded list of required packages. New default standard-app-packages package adds dependencies on the core Meteor stack. This package can be removed to make an app with only parts of the Meteor stack. standard-app-packages will be automatically added to a project when it is updated to Meteor 0.6.5.
1899
1900Custom app packages in the packages directory are no longer automatically used. They must be explicitly added to the app with meteor add <packagename>. To help with the transition, all packages in the packages directory will be automatically added to the project when it is updated to Meteor 0.6.5.
1901
1902New "unipackage" on-disk format for built packages. Compiled packages are cached and rebuilt only when their source or dependencies change.
1903
1904Add "unordered" and "weak" package dependency modes to allow circular package dependencies and conditional code inclusion.
1905
1906New API (_transitional_registerBuildPlugin) for declaring compilers, preprocessors, and file extension handlers. These new build plugins are full compilation targets in their own right, and have their own namespace, source files, NPM requirements, and package dependencies. The old register_extension API is deprecated. Please note that the package.js format and especially _transitional_registerBuildPlugin are not frozen interfaces and are subject to change in future releases.
1907
1908Add api.imply, which allows one package to "imply" another. If package A implies package B, then anything that depends on package A automatically depends on package B as well (and receives package B's imports). This is useful for creating umbrella packages (standard-app-packages) or sometimes for factoring common code out of related packages (accounts-base).
1909
1910Move HTTP serving out of the server bootstrap and into the webapp package. This allows building Meteor apps that are not web servers (eg. command line tools, DDP clients, etc.). Connect middlewares can now be registered on the new WebApp.connectHandlers instead of the old __meteor_bootstrap__.app.
1911
1912The entire Meteor build process now has first-class source map support. A source map is maintained for every source file as it passes through the build pipeline. Currently, the source maps are only served in development mode. Not all web browsers support source maps yet and for those that do, you may have to turn on an option to enable them. Source maps will always be used when reporting exceptions on the server.
1913
1914Update the coffeescript package to generate source maps.
1915
1916Add new Assets API and private subdirectory for including and accessing static assets on the server. http://docs.meteor.com/#assets
1917
1918Add Meteor.disconnect. Call this to disconnect from the server and stop all live data updates. #1151
1919
1920Add Match.Integer to check for 32-bit signed integers.
1921
1922Meteor.connect has been renamed to DDP.connect and is now fully supported on the server. Server-to-server DDP connections use websockets, and can be used for both method calls and subscriptions.
1923
1924Rename Meteor.default_connection to Meteor.connection and Meteor.default_server to Meteor.server.
1925
1926Rename Meteor.http to HTTP.
1927
1928ROOT_URL may now have a path part. This allows serving multiple Meteor apps on the same domain.
1929
1930Support creating named unmanaged collections with new Meteor.Collection("name", {connection: null}).
1931
1932New Log function in the logging package which prints with timestamps, color, filenames and linenumbers.
1933
1934Include http response in errors from oauth providers. #1246
1935
1936The observe callback movedTo now has a fourth argument before.
1937
1938Move NPM control files for packages from .npm to .npm/package. This is to allow build plugins such as coffeescript to depend on NPM packages. Also, when removing the last NPM dependency, clean up the .npm dir.
1939
1940Remove deprecated Meteor.is_client and Meteor.is_server variables.
1941
1942Implement "meteor bundle --debug" #748
1943
1944Add forceApprovalPrompt option to Meteor.loginWithGoogle. #1226
1945
1946Make server-side Mongo inserts, updates, and removes run asynchronously when a callback is passed.
1947
1948Improve memory usage when calling findOne() on the server.
1949
1950Delete login tokens from server when user logs out.
1951
1952Rename package compatibility mode option to add_files from raw to bare.
1953
1954Fix Mongo selectors of the form: {$regex: /foo/}.
1955
1956Fix Spark memory leak. #1157
1957
1958Fix EPIPEs during dev mode hot code reload.
1959
1960Fix bug where we would never quiesce if we tried to revive subs that errored out (5e7138d)
1961
1962Fix bug where this.fieldname in handlebars template might refer to a helper instead of a property of the current data context. #1143
1963
1964Fix submit events on IE8. #1191
1965
1966Handle Meteor.loginWithX being called with a callback but no options. #1181
1967
1968Work around a Chrome bug where hitting reload could cause a tab to lose the DDP connection and never recover. #1244
1969
1970Upgraded dependencies:
1971
1972Node from 0.8.18 to 0.8.24
1973MongoDB from 2.4.3 to 2.4.4, now with SSL support
1974CleanCSS from 0.8.3 to 1.0.11
1975Underscore from 1.4.4 to 1.5.1
1976Fibers from 1.0.0 to 1.0.1
1977MongoDB Driver from 1.3.7 to 1.3.17
1978Patches contributed by GitHub users btipling, mizzao, timhaines and zol.
1979
1980v0.6.4.1, 2013-Jul-19
1981
1982Update mongodb driver to use version 0.2.1 of the bson module.
1983v0.6.4, 2013-Jun-10
1984
1985Separate OAuth flow logic from Accounts into separate packages. The facebook, github, google, meetup, twitter, and weibo packages can be used to perform an OAuth exchange without creating an account and logging in. #1024
1986
1987If you set the DISABLE_WEBSOCKETS environment variable, browsers will not attempt to connect to your app using Websockets. Use this if you know your server environment does not properly proxy Websockets to reduce connection startup time.
1988
1989Make Meteor.defer work in an inactive tab in iOS. #1023
1990
1991Allow new Random instances to be constructed with specified seed. This can be used to create repeatable test cases for code that picks random values. #1033
1992
1993Fix CoffeeScript error reporting to include source file and line number again. #1052
1994
1995Fix Mongo queries which nested JavaScript RegExp objects inside $or. #1089
1996
1997Upgraded dependencies:
1998
1999Underscore from 1.4.2 to 1.4.4 #776
2000http-proxy from 0.8.5 to 0.10.1 #513
2001connect from 1.9.2 to 2.7.10
2002Node mongodb client from 1.2.13 to 1.3.7 #1060
2003Patches contributed by GitHub users awwx, johnston, and timhaines.
2004
2005v0.6.3, 2013-May-15
2006
2007Add new check package for ensuring that a value matches a required type and structure. This is used to validate untrusted input from the client. See http://docs.meteor.com/#match for details.
2008
2009Use Websockets by default on supported browsers. This reduces latency and eliminates the constant network spinner on iOS devices.
2010
2011With autopublish on, publish many useful fields on Meteor.users.
2012
2013Files in the client/compatibility/ subdirectory of a Meteor app do not get wrapped in a new variable scope. This is useful for third-party libraries which expect var statements at the outermost level to be global.
2014
2015Add synthetic tap event for use on touch enabled devices. This is a replacement for click that fires immediately.
2016
2017When using the http package synchronously on the server, errors are thrown rather than passed in result.error
2018
2019The manager option to the Meteor.Collection constructor is now called connection. The old name still works for now. #987
2020
2021The localstorage-polyfill smart package has been replaced by a localstorage package, which defines a Meteor._localStorage API instead of trying to replace the DOM window.localStorage facility. (Now, apps can use the existence of window.localStorage to detect if the full localStorage API is supported.) #979
2022
2023Upgrade MongoDB from 2.2.1 to 2.4.3.
2024
2025Upgrade CoffeeScript from 1.5.0 to 1.6.2. #972
2026
2027Faster reconnects when regaining connectivity. #696
2028
2029Email.send has a new headers option to set arbitrary headers. #963
2030
2031Cursor transform functions on the server no longer are required to return objects with correct _id fields. #974
2032
2033Rework observe() callback ordering in minimongo to improve fiber safety on the server. This makes subscriptions on server to server DDP more usable.
2034
2035Use binary search in minimongo when updating ordered queries. #969
2036
2037Fix EJSON base64 decoding bug. #1001
2038
2039Support appcache on Chromium. #958
2040
2041Patches contributed by GitHub users awwx, jagill, spang, and timhaines.
2042
2043v0.6.2.1, 2013-Apr-24
2044
2045When authenticating with GitHub, include a user agent string. This unbreaks "Sign in with GitHub"
2046Patch contributed by GitHub user pmark.
2047
2048v0.6.2, 2013-Apr-16
2049
2050Better error reporting:
2051
2052Capture real stack traces for Meteor.Error.
2053Report better errors with misconfigured OAuth services.
2054Add per-package upgrade notices to meteor update.
2055
2056Experimental server-to-server DDP support: Meteor.connect on the server will connect to a remote DDP endpoint via WebSockets. Method calls should work fine, but subscriptions and minimongo on the server are still a work in progress.
2057
2058Upgrade d3 from 2.x to 3.1.4. See https://github.com/mbostock/d3/wiki/Upgrading-to-3.0 for compatibility notes.
2059
2060Allow CoffeeScript to set global variables when using use strict. #933
2061
2062Return the inserted documented ID from LocalCollection.insert. #908
2063
2064Add Weibo token expiration time to services.weibo.expiresAt.
2065
2066Spiderable.userAgentRegExps can now be modified to change what user agents are treated as spiders by the spiderable package.
2067
2068Prevent observe callbacks from affecting the arguments to identical observes. #855
2069
2070Fix meteor command line tool when run from a home directory with spaces in its name. If you previously installed meteor release 0.6.0 or 0.6.1 you'll need to uninstall and reinstall meteor to support users with spaces in their usernames (see https://github.com/meteor/meteor/blob/master/README.md#uninstalling-meteor)
2071
2072Patches contributed by GitHub users andreas-karlsson, awwx, jacott, joshuaconner, and timhaines.
2073
2074v0.6.1, 2013-Apr-08
2075
2076Correct NPM behavior in packages in case there is a node_modules directory somewhere above the app directory. #927
2077
2078Small bug fix in the low-level routepolicy package.
2079
2080Patches contributed by GitHub users andreas-karlsson and awwx.
2081
2082v0.6.0, 2013-Apr-04
2083
2084Meteor has a brand new distribution system! In this new system, code-named Engine, packages are downloaded individually and on demand. All of the packages in each official Meteor release are prefetched and cached so you can still use Meteor while offline. You can have multiple releases of Meteor installed simultaneously; apps are pinned to specific Meteor releases. All meteor commands accept a --release argument to specify which release to use; meteor update changes what release the app is pinned to. Inside an app, the name of the release is available at Meteor.release. When running Meteor directly from a git checkout, the release is ignored.
2085
2086Variables declared with var at the outermost level of a JavaScript source file are now private to that file. Remove the var to share a value between files.
2087
2088Meteor now supports any x86 (32- or 64-bit) Linux system, not just those which use Debian or RedHat package management.
2089
2090Apps may contain packages inside a top-level directory named packages.
2091
2092Packages may depend on NPM modules, using the new Npm.depends directive in their package.js file. (Note: if the NPM module has architecture-specific binary components, bundles built with meteor bundle or meteor deploy will contain the components as built for the developer's platform and may not run on other platforms.)
2093
2094Meteor's internal package tests (as well as tests you add to your app's packages with the unsupported Tinytest framework) are now run with the new command meteor test-packages.
2095
2096{{#each}} helper can now iterate over falsey values without throwing an exception. #815, #801
2097
2098{{#with}} helper now only includes its block if its argument is not falsey, and runs an {{else}} block if provided if the argument is falsey. #770, #866
2099
2100Twitter login now stores profile_image_url and profile_image_url_https attributes in the user.services.twitter namespace. #788
2101
2102Allow packages to register file extensions with dots in the filename.
2103
2104When calling this.changed in a publish function, it is no longer an error to clear a field which was never set. #850
2105
2106Deps API
2107
2108Add dep.depend(), deprecate Deps.depend(dep) and dep.addDependent().
2109If first run of Deps.autorun throws an exception, stop it and don't rerun. This prevents a Spark exception when template rendering fails ("Can't call 'firstNode' of undefined").
2110If an exception is thrown during Deps.flush with no stack, the message is logged instead. #822
2111When connecting to MongoDB, use the JavaScript BSON parser unless specifically requested in MONGO_URL; the native BSON parser sometimes segfaults. (Meteor only started using the native parser in 0.5.8.)
2112
2113Calls to the update collection function in untrusted code may only use a whitelisted list of modifier operators.
2114
2115Patches contributed by GitHub users awwx, blackcoat, cmather, estark37, mquandalle, Primigenus, raix, reustle, and timhaines.
2116
2117v0.5.9, 2013-Mar-14
2118
2119Fix regression in 0.5.8 that prevented users from editing their own profile. #809
2120
2121Fix regression in 0.5.8 where Meteor.loggingIn() would not update reactively. #811
2122
2123v0.5.8, 2013-Mar-13
2124
2125Calls to the update and remove collection functions in untrusted code may no longer use arbitrary selectors. You must specify a single document ID when invoking these functions from the client (other than in a method stub).
2126
2127You may still use other selectors when calling update and remove on the server and from client method stubs, so you can replace calls that are no longer supported (eg, in event handlers) with custom method calls.
2128
2129The corresponding update and remove callbacks passed to allow and deny now take a single document instead of an array.
2130
2131Add new appcache package. Add this package to your project to speed up page load and make hot code reload smoother using the HTML5 AppCache API. See http://docs.meteor.com/#appcache for details.
2132
2133Rewrite reactivity library. Meteor.deps is now Deps and has a new API. Meteor.autorun and Meteor.flush are now called Deps.autorun and Deps.flush (the old names still work for now). The other names under Meteor.deps such as Context no longer exist. The new API is documented at http://docs.meteor.com/#deps
2134
2135You can now provide a transform option to collections, which is a function that documents coming out of that collection are passed through. find, findOne, allow, and deny now take transform options, which may override the Collection's transform. Specifying a transform of null causes you to receive the documents unmodified.
2136
2137Publish functions may now return an array of cursors to publish. Currently, the cursors must all be from different collections. #716
2138
2139User documents have id's when onCreateUser and validateNewUser hooks run.
2140
2141Encode and store custom EJSON types in MongoDB.
2142
2143Support literate CoffeeScript files with the extension .litcoffee. #766
2144
2145Add new login service provider for Meetup.com in accounts-meetup package.
2146
2147If you call observe or observeChanges on a cursor created with the reactive: false option, it now only calls initial add callbacks and does not continue watching the query. #771
2148
2149In an event handler, if the data context is falsey, default it to {} rather than to the global object. #777
2150
2151Allow specifying multiple event handlers for the same selector. #753
2152
2153Revert caching header change from 0.5.5. This fixes image flicker on redraw.
2154
2155Stop making Session available on the server; it's not useful there. #751
2156
2157Force URLs in stack traces in browser consoles to be hyperlinks. #725
2158
2159Suppress spurious changed callbacks with empty fields from Cursor.observeChanges.
2160
2161Fix logic bug in template branch matching. #724
2162
2163Make spiderable user-agent test case insensitive. #721
2164
2165Fix several bugs in EJSON type support:
2166
2167Fix {$type: 5} selectors for binary values on browsers that do not support Uint8Array.
2168Fix EJSON equality on falsey values.
2169Fix for returning a scalar EJSON type from a method. #731
2170Upgraded dependencies:
2171
2172mongodb driver to version 1.2.13 (from 0.1.11)
2173mime module removed (it was unused)
2174Patches contributed by GitHub users awwx, cmather, graemian, jagill, jmhredsox, kevinxucs, krizka, mitar, raix, and rasmuserik.
2175
2176v0.5.7, 2013-Feb-21
2177
2178The DDP wire protocol has been redesigned.
2179
2180The handshake message is now versioned. This breaks backwards compatibility between sites with Meteor.connect(). Older meteor apps can not talk to new apps and vice versa. This includes the madewith package, apps using madewith must upgrade.
2181
2182New EJSON package allows you to use Dates, Mongo ObjectIDs, and binary data in your collections and Session variables. You can also add your own custom datatypes.
2183
2184Meteor now correctly represents empty documents in Collections.
2185
2186There is an informal specification in packages/livedata/DDP.md.
2187
2188Breaking API changes
2189
2190Changed the API for observe. Observing with added, changed and removed callbacks is now unordered; for ordering information use addedAt, changedAt, removedAt, and movedTo. Full documentation is in the observe docs. All callers of observe need to be updated.
2191
2192Changed the API for publish functions that do not return a cursor (ie functions that call this.set and this.unset). See the publish docs for the new API.
2193
2194New Features
2195
2196Added new observeChanges API for keeping track of the contents of a cursor more efficiently.
2197
2198There is a new reactive function on subscription handles: ready() returns true when the subscription has received all of its initial documents.
2199
2200Added Session.setDefault(key, value) so you can easily provide initial values for session variables that will not be clobbered on hot code push.
2201
2202You can specify that a collection should use MongoDB ObjectIDs as its _id fields for inserts instead of strings. This allows you to use Meteor with existing MongoDB databases that have ObjectID _ids. If you do this, you must use EJSON.equals() for comparing equality instead of ===. See http://docs.meteor.com/#meteor_collection.
2203
2204New random package provides several functions for generating random values. The new Random.id() function is used to provide shorter string IDs for MongoDB documents. Meteor.uuid() is deprecated.
2205
2206Meteor.status() can return the status failed if DDP version negotiation fails.
2207
2208Major Performance Enhancements
2209
2210Rewrote subscription duplication detection logic to use a more efficient algorithm. This significantly reduces CPU usage on the server during initial page load and when dealing with large amounts of data.
2211
2212Reduced unnecessary MongoDB re-polling of live queries. Meteor no longer polls for changes on queries that specify _id when updates for a different specific _id are processed. This drastically improves performance when dealing with many subscriptions and updates to individual objects, such as those generated by the accounts-base package on the Meteor.users collection.
2213
2214Upgraded UglifyJS2 to version 2.2.5
2215
2216Patches contributed by GitHub users awwx and michaelglenadams.
2217
2218v0.5.6, 2013-Feb-15
2219
2220Fix 0.5.5 regression: Minimongo selectors matching subdocuments under arrays did not work correctly.
2221
2222Some Bootstrap icons should have appeared white.
2223
2224Patches contributed by GitHub user benjaminchelli.
2225
2226v0.5.5, 2013-Feb-13
2227
2228Deprecate Meteor.autosubscribe. Meteor.subscribe now works within Meteor.autorun.
2229
2230Allow access to Meteor.settings.public on the client. If the JSON file you gave to meteor --settings includes a field called public, that field will be available on the client as well as the server.
2231
2232@import works in less. Use the .lessimport file extension to make a less file that is ignored by preprocessor so as to avoid double processing. #203
2233
2234Upgrade Fibers to version 1.0.0. The Fiber and Future symbols are no longer exposed globally. To use fibers directly you can use: var Fiber = __meteor_bootstrap__.require('fibers'); and var Future = __meteor_bootstrap__.require('fibers/future');
2235
2236Call version 1.1 of the Twitter API when authenticating with OAuth. accounts-twitter users have until March 5th, 2013 to upgrade before Twitter disables the old API. #527
2237
2238Treat Twitter ids as strings, not numbers, as recommended by Twitter. #629
2239
2240You can now specify the _id field of a document passed to insert. Meteor still auto-generates _id if it is not present.
2241
2242Expose an invalidated flag on Meteor.deps.Context.
2243
2244Populate user record with additional data from Facebook and Google. #664
2245
2246Add Facebook token expiration time to services.facebook.expiresAt. #576
2247
2248Allow piping a password to meteor deploy on stdin. #623
2249
2250Correctly type cast arguments to handlebars helper. #617
2251
2252Fix leaked global userId symbol.
2253
2254Terminate phantomjs properly on error when using the spiderable package. #571
2255
2256Stop serving non-cachable files with caching headers. #631
2257
2258Fix race condition if server restarted between page load and initial DDP connection. #653
2259
2260Resolve issue where login methods sometimes blocked future methods. #555
2261
2262Fix Meteor.http parsing of JSON responses on Firefox. #553
2263
2264Minimongo no longer uses eval. #480
2265
2266Serve 404 for /app.manifest. This allows experimenting with the upcoming appcache smart package. #628
2267
2268Upgraded many dependencies, including:
2269
2270node.js to version 0.8.18
2271jquery-layout to version 1.3.0RC
2272Twitter Bootstrap to version 2.3.0
2273Less to version 1.3.3
2274Uglify to version 2.2.3
2275useragent to version 2.0.1
2276Patches contributed by GitHub users awwx, bminer, bramp, crunchie84, danawoodman, dbimmler, Ed-von-Schleck, geoffd123, jperl, kevee, milesmatthias, Primigenus, raix, timhaines, and xenolf.
2277
2278v0.5.4, 2013-Jan-08
2279
2280Fix 0.5.3 regression: meteor run could fail on OSX 10.8 if environment variables such as DYLD_LIBRARY_PATH are set.
2281v0.5.3, 2013-Jan-07
2282
2283Add --settings argument to meteor deploy and meteor run. This allows you to specify deployment-specific information made available to server code in the variable Meteor.settings.
2284
2285Support unlimited open tabs in a single browser. Work around the browser per-hostname connection limit by using randomized hostnames for deployed apps. #131
2286
2287minimongo improvements:
2288
2289Allow observing cursors with skip or limit. #528
2290Allow sorting on dotted.sub.keys. #533
2291Allow querying specific array elements (foo.1.bar).
2292$and, $or, and $nor no longer accept empty arrays (for consistency with Mongo)
2293Re-rendering a template with Spark no longer reverts changes made by users to a preserved form element. Instead, the newly rendered value is only applied if it is different from the previously rendered value. Additionally, elements with type other than TEXT can now have reactive values (eg, the labels on submit buttons can now be reactive). #510 #514 #523 #537 #558
2294
2295Support JavaScript RegExp objects in selectors in Collection write methods on the client, eg myCollection.remove({foo: /bar/}). #346
2296
2297meteor command-line improvements:
2298
2299Improve error message when mongod fails to start.
2300The NODE_OPTIONS environment variable can be used to pass command-line flags to node (eg, --debug or --debug-brk to enable the debugger).
2301Die with error if an app name is mistakenly passed to meteor reset.
2302Add support for "offline" access tokens with Google login. #464 #525
2303
2304Don't remove serviceData fields from previous logins when logging in with an external service.
2305
2306Improve OAuth1Binding to allow making authenticated API calls to OAuth1 providers (eg Twitter). #539
2307
2308New login providers automatically work with {{loginButtons}} without needing to edit the accounts-ui-unstyled package. #572
2309
2310Use Content-Type: application/json by default when sending JSON data with Meteor.http.
2311
2312Improvements to jsparse: hex literals, keywords as property names, ES5 line continuations, trailing commas in object literals, line numbers in error messages, decimal literals starting with ., regex character classes with slashes.
2313
2314Spark improvements:
2315
2316Improve rendering of elements on IE. #496 Don't lose nested data contexts in IE9/10 after two seconds. #458 Don't print a stack trace if DOM nodes are manually removed from the document without calling Spark.finalize. #392 Always use the autoReconnect flag when connecting to Mongo. #425 Fix server-side observe with no added callback. #589 Fix re-sending method calls on reconnect. #538 Remove deprecated /sockjs URL support from Meteor.connect. Avoid losing a few bits of randomness in UUID v4 creation. #519 Update clean-css package from 0.8.2 to 0.8.3, fixing minification of 0% values in hsl colors. #515 Patches contributed by GitHub users Ed-von-Schleck, egtann, jwulf, lvbreda, martin-naumann, meawoppl, nwmartin, timhaines, and zealoushacker. v0.5.2, 2012-Nov-27 Fix 0.5.1 regression: Cursor observe works during server startup. #507 v0.5.1, 2012-Nov-20 Speed up server-side subscription handling by avoiding redundant work when the same Mongo query is observed multiple times concurrently (eg, by multiple users subscribing to the same subscription), and by using a simpler "unordered" algorithm. Meteor now waits to invoke method callbacks until all the data written by the method is available in the local cache. This way, method callbacks can see the full effects of their writes. This includes the callbacks passed to Meteor.call and Meteor.apply, as well as to the Meteor.Collection insert/update/remove methods. If you want to process the method's result as soon as it arrives from the server, even if the method's writes are not available yet, you can now specify an onResultReceived callback to Meteor.apply. Rework latency compensation to show server data changes sooner. Previously, as long as any method calls were in progress, Meteor would buffer all data changes sent from the server until all methods finished. Meteor now only buffers writes to documents written by client stubs, and applies the writes as soon as all methods that wrote that document have finished. Meteor.userLoaded() and {{currentUserLoaded}} have been removed. Previously, during the login process on the client, Meteor.userId() could be set but the document at Meteor.user() could be incomplete. Meteor provided the function Meteor.userLoaded() to differentiate between these states. Now, this in-between state does not occur: when a user logs in, Meteor.userId() only is set once Meteor.user() is fully loaded. New reactive function Meteor.loggingIn() and template helper {{loggingIn}}; they are true whenever some login method is in progress. accounts-ui now uses this to show an animation during login. The sass CSS preprocessor package has been removed. It was based on an unmaintained NPM module which did not implement recent versions of the Sass language and had no error handling. Consider using the less or stylus packages instead. #143 Meteor.setPassword is now called Accounts.setPassword, matching the documentation and original intention. #454 Passing the wait option to Meteor.apply now waits for all in-progress method calls to finish before sending the method, instead of only guaranteeing that its callback occurs after the callbacks of in-progress methods. New function Accounts.callLoginMethod which should be used to call custom login handlers (such as those registered with Accounts.registerLoginHandler). The callbacks for Meteor.loginWithToken and Accounts.createUser now match the other login callbacks: they are called with error on error or with no arguments on success. Fix bug where method calls could be dropped during a brief disconnection. #339 Prevent running the meteor command-line tool and server on unsupported Node versions. Fix Minimongo query bug with nested objects. #455 In accounts-ui, stop page layout from changing during login. Use path.join instead of / in paths (helpful for the unofficial Windows port) #303 The spiderable package serves pages to facebookexternalhit #411 Fix error on Firefox with DOM Storage disabled. Avoid invalidating listeners if setUserId is called with current value. Upgrade many dependencies, including: MongoDB 2.2.1 (from 2.2.0) underscore 1.4.2 (from 1.3.3) bootstrap 2.2.1 (from 2.1.1) jQuery 1.8.2 (from 1.7.2) less 1.3.1 (from 1.3.0) stylus 0.30.1 (from 0.29.0) coffee-script 1.4.0 (from 1.3.3) Patches contributed by GitHub users ayal, dandv, possibilities, TomWij, tmeasday, and workmad3. v0.5.0, 2012-Oct-17 This release introduces Meteor Accounts, a full-featured auth system that supports fine-grained user-based control over database reads and writes federated login with any OAuth provider (with built-in support for Facebook, GitHub, Google, Twitter, and Weibo) secure password login email validation and password recovery an optional set of UI widgets implementing standard login/signup/password change/logout flows When you upgrade to Meteor 0.5.0, existing apps will lose the ability to write to the database from the client. To restore this, either: configure each of your collections with collection.allow and collection.deny calls to specify which users can perform which write operations, or add the insecure smart package (which is included in new apps by default) to restore the old behavior where anyone can write to any collection which has not been configured with allow or deny For more information on Meteor Accounts, see http://docs.meteor.com/#dataandsecurity and http://docs.meteor.com/#accounts_api The new function Meteor.autorun allows you run any code in a reactive context. See http://docs.meteor.com/#meteor_autorun Arrays and objects can now be stored in the Session; mutating the value you retrieve with Session.get does not affect the value in the session. On the client, Meteor.apply takes a new wait option, which ensures that no further method calls are sent to the server until this method is finished; it is used for login and logout methods in order to keep the user ID well-defined. You can also specifiy an onReconnect handler which is run when re-establishing a connection; Meteor Accounts uses this to log back in on reconnect. Meteor now provides a compatible replacement for the DOM localStorage facility that works in IE7, in the localstorage-polyfill smart package. Meteor now packages the D3 library for manipulating documents based on data in a smart package called d3. Meteor.Collection now takes its optional manager argument (used to associate a collection with a server you've connected to with Meteor.connect) as a named option. (The old call syntax continues to work for now.) Fix a bug where trying to immediately resubscribe to a record set after unsubscribing could fail silently. Better error handling for failed Mongo writes from inside methods; previously, errors here could cause clients to stop processing data from the server. Patches contributed by GitHub users bradens, dandv, dybskiy, possibilities, zhangcheng, and 75lb. v0.4.2, 2012-Oct-02 Fix connection failure on iOS6. SockJS 0.3.3 includes this fix. The new preserve-inputs package, included by default in new Meteor apps, restores the pre-v0.4.0 behavior of "preserving" all form input elements by ID and name during re-rendering; users who want more precise control over preservation can still use the APIs added in v0.4.0. A few changes to the Meteor.absoluteUrl function: Added a replaceLocalhost option. The ROOT_URL environment variable is respected by meteor run. It is now included in all apps via the meteor package. Apps that explicitly added the now-deprecated absolute-url smart package will log a deprecation warning. Upgrade Node from 0.8.8 to 0.8.11. If a Handlebars helper function foo returns null, you can now run do {{foo.bar}} without error, just like when foo is a non-existent property. If you pass a non-scalar object to Session.set, an error will now be thrown (matching the behavior of Session.equals). #215 HTML pages are now served with a charset=utf-8 Content-Type header. #264 The contents of <select> tags can now be reactive even in IE 7 and 8. The meteor tool no longer gets confused if a parent directory of your project is named public. #352 Fix a race condition in the spiderable package which could include garbage in the spidered page. The REPL run by admin/node.sh no longer crashes Emacs M-x shell on exit. Refactor internal reload API. New internal jsparse smart package. Not yet exposed publicly. Patch contributed by GitHub user yanivoliver. v0.4.1, 2012-Sep-24 New email smart package, with Email.send API. Upgrade Node from 0.6.17 to 0.8.8, as well as many Node modules in the dev bundle; those that are user-exposed are: coffee-script: 1.3.3 (from 1.3.1) stylus: 0.29.0 (from 0.28.1) nib: 0.8.2 (from 0.7.0) All publicly documented APIs now use camelCase rather than under_scores. The old spellings continue to work for now. New names are: Meteor.isClient/isServer this.isSimulation inside a method invocation Meteor.deps.Context.onInvalidate Meteor.status().retryCount/retryTime Spark improvements Optimize selector matching for event maps. Fix Spark._currentRenderer behavior in timer callbacks. Fix bug caused by interaction between Template.foo.preserve and {{#constant}}. #323 Allow {{#each}} over a collection of objects without _id. #281 Spark now supports Firefox 3.6. Added a script to build a standalone spark.js that does not depend on Meteor (it depends on jQuery or Sizzle if you need IE7 support, and otherwise is fully standalone). Database writes from within Meteor.setTimeout/setInterval/defer will be batched with other writes from the current method invocation if they start before the method completes. Make Meteor.Cursor.forEach fully synchronous even if the user's callback yields. #321. Recover from exceptions thrown in Meteor.publish handlers. Upgrade bootstrap to version 2.1.1. #336, #337, #288, #293 Change the implementation of the meteor deploy password prompt to not crash Emacs M-x shell. Optimize LocalCollection.remove(id) to be O(1) rather than O(n). Optimize client-side database performance when receiving updated data from the server outside of method calls. Better error reporting when a package in .meteor/packages does not exist. Better error reporting for coffeescript. #331 Better error handling in Handlebars.Exception. Patches contributed by GitHub users fivethirty, tmeasday, and xenolf. v0.4.0, 2012-Aug-30 Merge Spark, a new live page update engine Breaking API changes Input elements no longer preserved based on id and name attributes. Use preserve instead. All Meteor.ui functions removed. Use Meteor.render, Meteor.renderList, and Spark functions instead. New template functions (eg. created, rendered, etc) may collide with existing helpers. Use Template.foo.helpers() to avoid conflicts. New syntax for declaring event maps. Use Template.foo.events({...}). For backwards compatibility, both syntaxes are allowed for now. New Template features Allow embedding non-Meteor widgets (eg. Google Maps) using {{#constant}} Callbacks when templates are rendered. See http://docs.meteor.com/#template_rendered Explicit control of which nodes are preserved during re-rendering. See http://docs.meteor.com/#template_preserve Easily find nodes within a template in event handlers and callbacks. See http://docs.meteor.com/#template_find Allow parts of a template to be independently reactive with the {{#isolate}} block helper. Use PACKAGE_DIRS environment variable to override package location. #227 Add absolute-url package to construct URLs pointing to the application. Allow modifying documents returned by observe callbacks. #209 Fix periodic crash after client disconnect. #212 Fix minimingo crash on dotted queries with undefined keys. #126 v0.3.9, 2012-Aug-07 Add spiderable package to allow web crawlers to index Meteor apps. meteor deploy uses SSL to protect application deployment. Fix stopImmediatePropagation(). #205 v0.3.8, 2012-Jul-12 HTTPS support Add force-ssl package to require site to load over HTTPS. Use HTTPS for install script and meteor update. Allow runtime configuration of default DDP endpoint. Handlebars improvements Implement dotted path traversal for helpers and methods. Allow functions in helper arguments. Change helper nesting rules to allow functions as arguments. Fix {{this.foo}} to never invoke helper foo. Make event handler this reflect the node that matched the selector instead of the event target node. Fix keyword arguments to helpers. Add nib support to stylus package. #175 Upgrade bootstrap to version 2.0.4. #173 Print changelog after meteor update. Fix mouseenter and mouseleave events. #224 Fix issue with spurious heartbeat failures on busy connections. Fix exception in minimongo when matching non-arrays using $all. #183 Fix serving an empty file when no cacheable assets exist. #179 v0.3.7, 2012-Jun-06 Better parsing of .html template files Allow HTML comments (<!-- -->) at top level Allow whitespace anywhere in open/close tag Provide names and line numbers on error More helpful error messages Form control improvements Fix reactive radio buttons in Internet Explorer. Fix reactive textareas to update consistently across browsers, matching text field behavior. http package bug fixes: Send correct Content-Type when POSTing params from the server. #172 Correctly detect JSON response Content-Type when a charset is present. Support Handlebars.SafeString. #160 Fix intermittent "Cursor is closed" mongo error. Fix "Cannot read property 'nextSibling' of null" error in certain nested templates. #142 Add heartbeat timer on the client to notice when the server silently goes away. v0.3.6, 2012-May-16 Rewrite event handling. this in event handlers now refers to the data context of the element that generated the event, not the top-level data context of the template where the event is declared. Add /websocket endpoint for raw websockets. Pass websockets through development mode proxy. Simplified API for Meteor.connect, which now receives a URL to a Meteor app rather than to a sockjs endpoint. Fix livedata to support subscriptions with overlapping documents. Update node.js to 0.6.17 to fix potential security issue. v0.3.5, 2012-Apr-28 Fix 0.3.4 regression: Call event map handlers on bubbled events. #107 v0.3.4, 2012-Apr-27 Add Twitter bootstrap package. #84 Add packages for sass and stylus CSS pre-processors. #40, #50 Bind events correctly on top level elements in a template. Fix dotted path selectors in minimongo. #88 Make backbone package also run on the server. Add bare option to coffee-script compilation so variables can be shared between multiple coffee-script file. #85 Upgrade many dependency versions. User visible highlights: node.js 0.6.15 coffee-script 1.3.1 less 1.3.0 sockjs 0.3.1 underscore 1.3.3 backbone 0.9.2 Several documentation fixes and test coverage improvements. v0.3.3, 2012-Apr-20 Add http package for making HTTP requests to remote servers. Add madewith package to put a live-updating Made with Meteor badge on apps. Reduce size of mongo database on disk (--smallfiles). Prevent unnecessary hot-code pushes on deployed apps during server migration. Fix issue with spaces in directory names. #39 Workaround browser caching issues in development mode by using query parameters on all JavaScript and CSS requests. Many documentation and test fixups. v0.3.2, 2012-Apr-10 Initial public launch