Version 5.1.0
October 9, 2026
Added
- GraphQL.
bookDocuments,bookDocumentandbookDocumentCountqueries, behind a new Book → Query for documents schema permission. ABookDocumentcarries the file's facts, the viewer resolution (resolution { viewer frameUrl … }),fileUrlanddownloadUrlsigned afresh for each request, and the renderedhtml(…), which takes the same options as a reference tag. Only enabled documents are returned, a query cannot change a document's access rule, and the author-facing warnings stay hidden outside dev mode, as they do on the page. - Documents relation fields now work in GraphQL, as
[BookDocumentInterface], in schemas that may read documents.
Fixed
- A login-gated CSV, Markdown, JSON or text document rendered inline wrote its contents into the page for guests too. A guest now gets the download card, whose link asks them to log in.
- A cached response — a
{% cache %}block, or a GraphQL response — could outlive the expiring signed URLs inside it. Book now shortens the cache to half the signature's lifetime.
Version 5.0.1
September 28, 2026
Security
- Fixed a vulnerability where anyone with Book's view permission could preview, resolve or embed any asset by ID, including files in volumes they had no access to — and see their contents, or a signed link to them. Every Documents action that takes an asset now requires Craft's permission to view it, and a Document field refuses a file the editor can't view or that is outside the field's own volumes. A missing asset and a forbidden one get the same answer.
Added
- A
linkSecretsetting, mixed into every file token. Changing it revokes every link Book has handed out, which previously needed the site's security key to change. It accepts an environment variable, and when empty (the default) links are signed exactly as before.
Version 5.0.0
August 23, 2026
Initial release.
Added
- Document element with reference tags —
{book:annual-report:render}renders a document inside CKEditor, Redactor or any other HTML field, with no template changes. Options travel in the tag:{book:annual-report:render(google,height=900)}. - Five viewers. The browser's own (PDF, images, audio, video), Google Docs Viewer, the Microsoft Office Web Viewer, Book's own server-side rendering for text-shaped formats, and a download card that is always available and is where everything else falls back to.
- Viewer resolution with reasons.
autopicks the best viewer that actually works for the format, in this environment, under this site's settings — and says what it ruled out and why, in the control panel before publishing rather than on the live page after. - Inline rendering of CSV and TSV (as a table, with delimiter sniffing and encoding repair), Markdown (purified), JSON (pretty-printed), and text, code and data files.
- Private assets. A file on a volume with no public URLs is served through Craft on a signed route, so the browser's PDF viewer and Book's own rendering work without making the volume public. Optional expiring signatures and a logged-in-users-only access rule.
- Two field types —
Documentfor a file configured on the entry,Documentsfor a relation to the library. - Twig API —
craft.book.embed(),.document(),.render(),.asset(),.url(),.all(),.resolve(),.downloadUrl(),.format(),.formats(),.viewers(),.extensions(),.embedCode(),.options(), plus abookfilter and function. - Front-end runtime — lazy loading, click-to-load consent for third-party viewers, a load timeout that turns a permanently blank frame into the file itself, fullscreen and print.
- Editor integrations — a CKEditor toolbar button and plugin, a Redactor plugin, a shared picker, and paste-a-file-URL-to-embed. HTML Purifier is taught about Book's data attributes.
- 18 formats recognised by extension and MIME type, with per-format viewer preferences.