+1

Thanks for spinning RC4, Dave! This one's clean, and the jQuery UI 404 that I 
hit in RC2 is gone, so the editor's date picker and tag autocomplete work 
again. I confirmed that in the running editor, not just the source.

The usual checks all pass:

- Signatures verify against BA59703C and the fingerprint matches the one in 
your email.
- SHA-512 and SHA-256 match on all four archives.
- LICENSE and NOTICE are present, the source archive matches the tag, and the 
tag points at 47c5cf0b like the announcement says.
- Builds clean on JDK 11, 325 tests, no failures.

I spent most of my time on the new one-time setup token, since that's the big 
change. It holds up end to end on a fresh install. An anonymous hit on the site 
redirects to the token page, a wrong token is rejected, and going straight at 
the installer URL redirects to the token page too, so there's no way around it. 
The real token from the log gets you into the installer, and once the first 
admin is created the gate closes for good: fresh sessions stop getting 
redirected, the old token is dead, registration is disabled, and the installer 
just renders an inert bootstrap tile.

I also read through the implementation and I like it. It stores a SHA-256 
digest instead of the raw token, compares in constant time, makes the token 
single use, binds the grant to the session with a 60 minute expiry, and sets 
no-store and no-referrer on the token page. The gate is enforced in a servlet 
filter and re-checked inside each installer action, so it's belt and suspenders 
(one of my favorite phrases from AI). Nothing sensitive ends up in a URL.

Beyond that I did the usual smoke test: logged in, created a weblog, published 
an entry, and it rendered on the blog. #190 is a nice hardening of the HTML 
subset link handling that now only lets http, https, and mailto through and 
drops things like javascript:, with good test coverage. The MySQL Connector/J 8 
installer fix reads correctly, though I couldn't exercise it since I was on 
Derby.

Two tiny things, neither a blocker: the source tarball ships a couple of empty 
logs/ directories, and the "changes since RC3" list in this email leaves out 
the Connector/J 8 commit (CHANGES.md does cover it, so the release notes 
themselves are fine).

Nice work getting this one across the line. :)

Matt


> On Sep 24, 2026, at 05:51, Dave <[email protected]> wrote:
> 
> Thanks for the vote and the feedback, Michael.
> 
> +1
> 
> We just need one more to get this out.
> 
> Dave
> 
> On Thu, Sep 17, 2026 at 8:24 PM Michael Bien <[email protected]> wrote:
> 
>> +1
>> 
>> sigs ok, content ok, smoketest worked.
>> 
>> 
>> notes for next release:
>> 
>> the one-time key could be also printed directly to System.out so that it
>> lands in the console logger and could be easily read from container logs
>> and/or console while testing.
>> 
>> notice file would need a date bump at some point ;)
>> 
>> -mbien
>> 
>> On 9/18/26 01:28, Dave wrote:
>>> Right o, here we go...
>>> 
>>> Please review and vote on Apache Roller 6.1.6, candidate RC4.
>>> 
>>> Source and convenience binary artifacts:
>>> https://dist.apache.org/repos/dist/dev/roller/roller-6.1/v6.1.6
>>> 
>>> Source tag: roller-6.1.6-rc4
>>> https://github.com/apache/roller/tree/roller-6.1.6-rc4
>>> 
>>> commit 47c5cf0bbfa00fe199bc743a7fb88df8e6b21d32
>>> KEYS: https://downloads.apache.org/roller/KEYS
>>> 
>>> Signing fingerprint: 3687 8574 1958 DE96 98FF DF4E 8FEC 6F9C BA59 703C
>>> 
>>> Release notes:
>>> https://github.com/apache/roller/blob/roller-6.1.6-rc4/CHANGES.md
>>> 
>>> Changes since RC3:
>>> - Secure initial Roller setup with a one-time operator token (#189)
>>> - Normalize links in HTML subset formatting (#190)
>>> - Format LDAP comment form values consistently (#191)
>>> - Override bootstrap .table-striped row shading (#188)
>>> - Add roller-release and roller-security AI skills (#186)
>>> 
>>> Reviewers may want to exercise the new initial-setup flow in particular:
>>> a first install now requires a one-time token printed to the server log,
>>> as does an upgrade that migrates the database schema.
>>> 
>>> The vote will remain open until at least 2026-09-20 20:00 EDT,
>>> allowing at least 72 hours for review under the normal process.
>>> 
>>> [ ] +1 Release this candidate
>>> [ ] +0 No opinion
>>> [ ] -1 Do not release, because [reason]
>>> 
>>> Dave Johnson
>> 
>> 

Reply via email to