Changelog
1.6.0
- Added:
generateandWebp generateextension configuration settings (both default on) that stop the processor from writing theAvif .webpor.aviffile next to each processed variant. The per-URLskip/Web P skipparameters still apply on top; sidecars already on disk keep being served until the processed images are cleared. See WebP/AVIF generation.Avif - Fixed: AVIF output quality is capped at 99. At quality 100
ImageMagick asks the AOM encoder for lossless AVIF, which it
rejects, so
qualityproduced no AVIF variant and a processed AVIF original requested withAvif = 100 q100failed with HTTP 500. - Changed (docs): the
qualitysetting label and the configuration docs state thatWebp 100produces lossless WebP, typically several times the size of the JPEG variant.
1.5.0
- Added: targeted deletion of processed variants by original path,
directory prefix, or glob pattern (
*/?) in the maintenance backend module -- similar to a CDN cache invalidation, instead of clearing the whole "processed" directory. Runs asynchronously with a confirmation dialog and refreshes the statistics afterward. Port of the main-branch feature. - Fixed: the maintenance module no longer risks exhausting memory on
large "processed" trees. Opening the module recomputed directory
statistics synchronously by materializing every file into an array
just to sort it once for the top-5 largest files -- on large
instances (measured 500k files) this could exhaust a typical 256M
PHP
memory_with a fatal error, on top of blocking page rendering. Statistics are now maintained as a size-bounded top-5 list during a single directory walk and fetched asynchronously instead of blockinglimit index. Port of the main-branch fix.Action () - Fixed: the maintenance module now respects TYPO3's backend dark
mode. Card headers, extension tags, and status badges used raw
Bootstrap
bg-*/text-utility classes that TYPO3's dark-mode gate never resets, rendering a solid near-white background regardless of the active color scheme. Replaced with TYPO3's ownbg-* badge-*modifiers and plaincard-.header - Fixed: the statistics JSON response no longer fails outright on a non-UTF-8 file name in "processed" -- invalid bytes are now substituted instead of aborting the whole response.
- Added: a "Performance model" section in the Introduction
contrasting this extension's render-vs-process decoupling with
TYPO3 core's
f:/image Image, which processes every referenced image synchronously during page render. Backed by a real measurement showing a 1,000x-50,000x per-image gap on cold render.Service - Changed (CI): replaced a temporary
rector/cap with arector ssch/floor once that release shipped the upstream container-API fix, and aligned the patch-coverage target withtypo3- rector: ^3. 15. 1 main(80%, was 100%).
1.4.1
- Fixed: every README/Documentation
Sourceexample used a non-existentSet View Helper fileargument -- onlypathis registered, so these examples failed at Fluid render time. Also removed a fictitiousformatconfval, added the real arguments (alt,title,class,attributes,set,lazyload) that were missing from both READMEs' parameter lists, and documented the nr:image:optimize/nr:image:analyze CLI commands and the on-upload compression feature, both previously undocumented anywhere. - Fixed: this changelog and
CHANGELOG.had fallen behind -- backfilled the missing 1.3.1 and 1.3.2 entries.md
1.4.0
- Added: on-upload compression.
Optimizesubscribes toOn Upload Listener AfterandFile Added Event Afterand runsFile Replaced Event optipng,gifsicle, andjpegoptiminline as a file lands, instead of relying on a separate cron/CLI pass. Port of the main-branch feature released in 2.2.2. - Added:
nr:andimage: optimize nr:console commands to cover existing files -- bulk optimization with filter/dry-run support, and a heuristic per-image savings report without modifying files. See Usage.image: analyze - Fixed: bulk
nr:/image: optimize nr:no longer abort the whole run when a single file fails. A stale FAL identifier (e.g. after an out-of-band folder rename) raised an uncaughtimage: analyze Runtimemid-run, discarding progress already made. Both commands now catch per-file failures, report them individually, and continue with the rest of the queue.Exception
Attention
Optimize is registered by default and
runs inline on every upload/replace. If your workflow depends
on uploads being stored byte-for-byte as they arrived,
disable the listener in your site package's Services.
before upgrading -- see the CHANGELOG's "Upgrading" note for
1.4.0.
1.3.2
- Fixed: animated GIFs are passed through unprocessed instead of being collapsed to their first frame. GIFs with more than one frame are excluded from variant processing; the original file is copied to the variant path and served as-is. WebP/AVIF sidecar generation is skipped for animated GIFs too. Port of the main-branch fix (2.x PR #143).
1.3.1
- Fixed: URL dimensions of
0(meaning "derive this side from the aspect ratio", asSourcealways writes both dimensions into the variant URL) were floored toSet View Helper 1by dimension clamping, turning height-based or width-based variants into 1x1 pixel images.0now derives the missing side from the aspect ratio, as it already did for an absent dimension.
1.3.0
- Added:
additionalextension configuration -- per-instance, opt-in, comma-separated list of absolute filesystem paths, outside FAL and TYPO3-internal locations, that are realpath-resolved and added to the path-validation allow-list. TYPO3'sTrusted Roots var/directory is now trusted automatically. Port of the fix onmain(2.4.0). See Additional trusted roots. - Added:
quality(defaultWebp 75) andquality(defaultAvif 60) extension configuration settings, so the WebP and AVIF sidecar variants can be tuned independently of the primary variant's quality. AVIF's steeper quality scale previously meant AVIF variants came out larger than WebP at the same numeric quality. Port of the fix onmain(2.4.0). See WebP/AVIF output quality. - Fixed: the Maintenance module's "clear processed images"
action failed whenever
processedwas a symlink to a shared volume -- a common Deployer/CI deployment layout. It validated the target withrealpath-equality, which resolves the symlink and never matches, so clearing failed on every symlinked deployment. The directory is now emptied in place instead of recreated, so the symlink survives. Port of the fix on() main(2.4.0).
1.2.0
- Added:
additionalextension configuration -- per-instance, opt-in, comma-separated list of directory names that, when found as a symlink directly inside a Local FAL storage's own base path (e.g.Trusted Storage Symlinks fileadmin/_), are resolved and added to the path-validation allow-list. Closes the gap where deployments relocate TYPO3 core's ownprocessed_ _processed_image cache onto local/ephemeral storage to keep it off shared/NFS storage, leaving a symlink behind that the FAL-storage basePath lookup cannot see. Default empty; keeps today's behaviour for every installation that doesn't opt in. See Trusted storage symlinks. - Fixed: images published via
public/_symlinks (extensionassets/<hash> Resources/assets) were rejected with HTTP 400. TYPO3 core publishes each extension'sPublic/ Resources/directory by symlinkingPublic/ public/_to a location outside the public webroot.assets/<hash>/ getdid not resolve these symlinks, so variant requests for e.g. an extension's default/fallback image failed even though the file is a legitimate part of the deployed application. Every immediate child ofAllowed Roots () _assetsis now resolved individually.
1.1.3
- Fixed: the
sourceViewHelper passes absolute URLs (Set http://,https://,//),data:URIs, and URLs carrying a query string through unchanged and renders them as a plain<img>tag. Previously such paths — e.g. the tokenizedeURLs fal_securedownload generates for files in non-public storages — were mangled into brokenID=dump File /processed/...variant paths. The access control of the generating extension stays intact; see Public images only: absolute URLs are passed through for the trade-off. Port of the fix onmain(2.2.4).
1.1.2
- Fixed: silent HTTP 400 responses now log their rejection reason
via
error_(URL-pattern mismatch and path-outside-allowed-roots branches).log () - Fixed: a transient
Storagefailure during early TYPO3 bootstrap no longer poisons the per-process allowed-roots cache; the degraded fallback is kept only for the current request.Repository - Fixed:
getis memoized per request, avoiding redundant lookups and repeated log lines.Allowed Roots () - Fixed: a filesystem-root public path (
/) no longer rejects every valid path.
1.1.1
- Fixed: processed image requests no longer return
HTTP 400 when
fileadmin(or any other Local FAL storage) is a symlink to an external location such as an NFS/EFS mount.isnow accepts any realpath-resolved path that lies within the TYPO3 public root or the realpath of any configured Local storage'sPath Within Allowed Roots base. Symlinks placed inside a storage that escape every allowed root -- e.g.Path fileadmin/->evil /etc-- continue to be rejected. Backport of the fix onmain, reported in issue #70. - Hardened: paths containing NUL bytes are rejected outright, closing a minor realpath-bypass via the not-yet-existing-path parent-walk branch.
- Changed (BC for subclasses and manual instantiators):
Netresearch\\gains a new requiredNr Image Optimize\\ Processor Storageconstructor parameter. Consumers that autowire the service (the default in TYPO3 12+) are unaffected; any code that extends the class or constructs it by hand must forward the new dependency.Repository - Changed (BC): dropped PHP 8.1 support. The TYPO3_12
maintenance branch now requires PHP 8.2 or newer
(TYPO3 v12 itself still supports PHP 8.1, but this
extension aligns with the
netresearch/tooling which requires PHP 8.2+).typo3- ci- workflows
1.1.0
New in version 1.1.0
Comprehensive quality review: security hardening, performance improvements, backend maintenance module, responsive srcset, and expanded test coverage.
- Added backend maintenance module with directory statistics, system requirements check, and clear processed images action.
- Added responsive width-based
srcsetgeneration as opt-in feature. - Added
widthparameter for custom breakpoints.Variants - Added
sizesparameter for responsive image sizing. - Added
fetchpriorityattribute for resource hints. - Added path traversal hardening and XSS prevention.
- Added DoS prevention via dimension and quality clamping.
- Added HTTP caching headers (
Cache-,Control: immutable ETag,Last-).Modified - Added 15 language localizations.
- Added 33+ unit tests, fuzz tests, and functional tests.
- Added full TYPO3 documentation structure.
1.0.3
- Fixed
Processor::TypeError for non-matching URLs (crawler/bot srcset descriptors).get Value From Mode ()
1.0.2
- Fixed nullable
dirnameaccess inSource.Set View Helper
1.0.1
- Added
ext_for classic installation.emconf. php
1.0.0
- Initial stable release.
- GitHub Actions CI workflows.
0.1.5
- Fixed
strtolowernull argument error.() - Fixed array offset access on boolean value.
- Allowed numeric characters in file extensions.
- Added extension icon.
- Corrected crop variant examples.
- Improved lazy loading behavior.