  • Disable session-based stage setting in Versioned (see #1578)
  • Deprecated FunctionalTest::useDraftSite(). You should use querystring args instead for setting stage.


Read Upgrading to Silverstripe 4 for a detailed step-by-step guide on upgrading your Silverstripe 3 project to Silverstripe 4. It describes how to use an automated upgrader tool to make the job easier. Please also note the 4.0.0 and 4.1.0 changelogs for a complete list of changes.

App folder name

The standard 'mysite' code naming convention has changed. Although existing sites can continue to use mysite/code to store their base project code, the recommendation and new default is to store code in app/src.

Additionally, we reinforce the recommendation to use psr-4 autoloading in your project to speed up class loading.

In order to upgrade a site to use app/src folder:

  • Rename the folder mysite to app and code to src.
  • Update your app/_config/mysite.yml config to the below:
Name: myproject
  project: app
  • add psr-4 for your root project files and namespace. An example composer.json below shows how this might look:
    "autoload": {
        "psr-4": {
            "TractorCow\\MyWebsite\\": "app/src/"
        "classmap": [
  • Ensure you flush your site with ?flush=all

Follow our step-by-step upgrading guide to perform this change automatically through our upgrade-code tool. In 5.0 the app folder will be fixed to app and cannot be soft-coded via mysite.yml

Disable session-based stage setting

When viewing a versioned record (usually pages) in "draft" mode, Silverstripe used to record this mode in the session for further requests. This has the advantage of transparently working on XHR and API requests, as well as authenticated users navigating through other views.

These subsequent requests no longer carried an explicit stage query parameter, which meant the same URL might show draft or live content depending on your session state. While most HTTP caching layers deal gracefully with this variation by disabling any caching when a session cookie is present, there is a small chance that draft content is exposed to unauthenticated users for the lifetime of the cache.

Due to this potential risk for information leakage, we have decided to only rely on the stage query parameter. If you are consistently using the built-in SiteTree->Link() and Controller->Link() methods to get URLs, this change likely won't affect you.

If you are manually concatenating URLs to Silverstripe controllers rather than through their Link() methods (in custom PHP or JavaScript), or have implemented your own Link() methods on controllers exposing versioned objects, you'll need to check your business logic.

Alternatively, you can opt-out of this security feature via YAML configuration:

  use_session: true

Check our versioning docs for more details.

New Versioned API

The following methods have been added to Versioned class:

  • withVersionedMode() Allows users to execute a closure which may internally modify the current stage, but will guarantee these changes are reverted safely on return. Helpful when temporarily performing a task in another stage or view mode.
  • get_draft_site_secured() / set_draft_site_secured() Enables the explicit toggle of draft site security. By setting this to false, you can expose a draft mode to unauthenticated users. Replaces unsecuredDraftSite session var.
  • get_default_reading_mode() / set_default_reading_mode() The default reading mode is now configurable. Any non-default reading mode must have querystring args to be visible. This will be the mode chosen for requests that do not have these args. Note that the default mode for CMS is now draft, but is live on the frontend.

A new class ReadingMode has also been added to assist with conversion of the reading mode between:

  • Reading mode string
  • DataQuery parameters
  • Querystring parameters

Link tracking

SiteTreeLinkTracking has been split and refactored into two extensions, and now no longer applies exclusively to HTMLContent areas on SiteTree objects, but now all DataObject classes.

  • SiteTreeLinkTracking -> Tracks links between any object and SiteTree objects, generated from [sitetree_link] shortcodes in html areas.
  • FileLinkTracking -> Tracks links between any object and File objects, generated from [image] and [file_link] shortcodes in html areas.

Note that the ImageTracking property has been deprecated in favour of FileTracking, which includes and tracks non-image files as well.

By default HasBrokenFile and HasBrokenLink properties are still supported, but only for SiteTree objects by default. Non-SiteTree objects will still have both FileTracking and LinkTracking relations available for tracking linked records.

In addition, File::BackLinkTracking() and SiteTree::BackLinkTracking() are now polymorphic, and may now both contain non-SiteTree objects. Polymorphic many_many through relations are currently experimentally supported.

User code which relies on SiteTree-only results for these properties will need to be updated to consider other types.

Additionally, the SiteTree_LinkTracking and SiteTree_ImageTracking tables no longer exist, and are replaced by the SiteTreeLink and FileLink many_many through joining classes instead. Code which relies on raw SQL queries to these tables will need to be updated.

SiteTreeFileExtension is deprecated, and has it's functionality baked directly into File dataobject.

New upgrader commands

Two new commands have been added to the Silverstripe upgrader tool: environment and reorganise.

environment allows you to convert your _ss_environment.php file to an equivalent .env file when migrating a Silverstripe 3 project to Silverstripe 4.

reorganise renames your mysite and app/code folders to app and app/src. It also warns you of any occurrence of mysite in your codebase.

cd ~/my-project-root
upgrade-code environment --write
upgrade-code reorganise --write

New GridField action menu

A new GridField_ActionMenu is included by default in GridFields configured with GridFieldConfig_RecordEditor or GridFieldConfig_RelationEditor. In addition to this GridFieldDeleteAction and GridFieldEditButton now implement GridField_ActionMenuItem, this means that any GridField that uses a config of or based on GridFieldConfig_RecordEditor or GridFieldConfig_RelationEditor will have an action menu on each item row with the 'Delete/Unlink' and 'Edit' actions moved into it.

If you wish to opt out of having this menu and the respective actions moved into it, you can remove the GridField_ActionMenu component from the config that is passed into your GridField.

// method 1: removing GridField_ActionMenu from a new GridField
$config = GridFieldConfig_RecordEditor::create();

$gridField = new GridField('Teams', 'Teams', $this->Teams(), $config);

// method 2: removing GridField_ActionMenu from an existing GridField

Versioned cache segmentation

SilverStripe\Core\Cache\CacheFactory now maintains separate cache pools for each versioned stage. This prevents developers from caching draft data and then accidentally exposing it on the live stage without potentially required authorisation checks. Unless you rely on caching across stages, you don't need to change your own code for this change to take effect. Note that cache keys will be internally rewritten, causing any existing cache items to become invalid when this change is deployed.

// Before:
$cache = Injector::inst()->get(CacheInterface::class . '.myapp');
$cache->set('my_key', 'Some draft content. Not for public viewing yet.');
// 'Some draft content. Not for public viewing yet'

// After:
$cache = Injector::inst()->get(CacheInterface::class . '.myapp');
$cache->set('my_key', 'Some draft content. Not for public viewing yet.');
// null

Data that is not content sensitive can be cached across stages by simply opting out of the segmented cache with the disable-container argument.

    factory: SilverStripe\Core\Cache\CacheFactory
      namespace: "MyInsensitiveData"
      disable-container: true

HTTP cache header changes


In order to support developers in making safe choices around HTTP caching, we're using a HTTPCacheControlMiddleware class to control if a response should be considered public or private. This is an abstraction on the HTTPResponse->addHeader() lowlevel API.

This change introduces smaller but necessary changes to HTTP caching headers sent by Silverstripe. If you are relying on HTTP caching in your implementation, or use modules such as silverstripe/controllerpolicy, please review the implications of these changes below.

In short, these APIs make it easier to express your caching preferences without running the risk of overriding essential core safety measures. Most commonly, these APIs will prevent HTTP caching of draft content.

It will also prevent caching of content generated with an active session, since the system can't tell whether session data was used to vary the output. In this case, it's up to the developer to opt-in to caching, after ensuring that certain execution paths are safe despite of using sessions.

The system behaviour does not guard against accidentally caching "private" content, since there are too many variations under which output could be considered private (e.g. a custom "approval" flag on a comment object). It is up to the developer to ensure caching is used appropriately there.

By default, Silverstripe sends headers which signal to HTTP caches that the response should be considered not cacheable.

See Developer Guide: Performance > HTTP Cache Headers for details on the new API.

Disabling legacy cache headers

In order to forcibly disable all deprecated HTTP APIs you can set the below config:

  ignoreDeprecatedCaching: true

This will ensure that any code paths that use the old API will not interefere with upgraded code that interferes with the new behaviour.

Example usage

Global opt-in for page content

Enable caching for all page content (through PageController).

-use SilverStripe\Control\HTTP;
+use SilverStripe\Control\Middleware\HTTPCacheControlMiddleware;
use SilverStripe\CMS\Controllers\ContentController;

class PageController extends ContentController
    public function init()
-        HTTP::set_cache_age(60);
+        HTTPCacheControlMiddleware::singleton()
+           ->enableCache()
+           ->setMaxAge(60); // 1 minute


Note: Silverstripe will still override this preference when a session is active, a CSRF token token is present, or draft content has been requested.

Opt-out for a particular controller action

If a controller output relies on session data, cookies, permission checks or other triggers for conditional output, you can disable caching either on a controller level (through init()) or for a particular action.

-use SilverStripe\Control\HTTP;
+use SilverStripe\Control\Middleware\HTTPCacheControlMiddleware;
use SilverStripe\CMS\Controllers\ContentController;

class PageController extends ContentController
    public function myprivateaction($request)
-        HTTP::set_cache_age(0);
+        HTTPCacheControlMiddleware::singleton()
+           ->disableCache();

        return $this->myPrivateResponse();

Note: Silverstripe will still override this preference when a session is active, a CSRF token token is present, or draft content has been requested.

Global opt-in, ignoring session (advanced)

This can be helpful in situations where forms are embedded on the website. Silverstripe will still override this preference when draft content has been requested. CAUTION: This mode relies on a developer examining each execution path to ensure that no session data is used to vary output.

Use case: By default, forms include a CSRF token which starts a session with a value that's unique to the visitor, which makes the output uncacheable. But any subsequent requests by this visitor will also carry a session, leading to uncacheable output for this visitor. This is the case even if the output does not contain any forms, and does not vary for this particular visitor.

-use SilverStripe\Control\HTTP;
+use SilverStripe\Control\Middleware\HTTPCacheControlMiddleware;
use SilverStripe\CMS\Controllers\ContentController;

class PageController extends ContentController
    public function init()
-        HTTP::set_cache_age(60);
+        HTTPCacheControlMiddleware::singleton()
+           ->enableCache($force=true) // DANGER ZONE
+           ->setMaxAge(60); // 1 minute


Detailed cache-control changes

  • Added Cache-Control: no-store header to default responses, to prevent intermediary HTTP proxies (e.g. CDNs) from caching unless developers opt-in
  • Removed Cache-Control: no-transform header from default responses
  • Removed Vary: Cookie as an unreliable cache buster, rely on the existing Cache-Control: no-store defaults instead
  • Removed Vary: Accept, since it's very uncommon to vary content on the Accept headers submitted through the request, and it can significantly decrease the likelihood of a cache hit. Note this is different from Vary: Accept-Encoding, which is important for compression (e.g. gzip), and usually added by other layers such as Apache's mod_gzip.
  • Removed Vary: X-Requested-With since it's only applicable when varying content based on the client context, mostly for returning different XHR responses as determined through Director::is_ajax().
  • No longer sets Last-Modified date in HTTP response headers in DataObject::__construct(). Uses ETag calculation based on response body which is more accurate, and resilient against partial and object caching which can produce stale Last-Modified values.
  • Deprecated HTTP::add_cache_headers(). Headers are added automatically by HTTPCacheControlMiddleware instead.
  • Deprecated HTTP::set_cache_age(). Use HTTPCacheControlMiddleware::singleton()->setMaxAge($age)
  • Deprecated HTTP.cache_ajax_requests. Use HTTPCacheControlMiddleware::disableCache() instead
  • Deprecated HTTP.modification_date. Handled by HTTPCacheControlMiddleware
  • Deprecated HTTP.disable_http_cache. Use HTTPCacheControlMiddleware.defaultState and defaultForcingLevel instead
  • Deprecated HTTP::register_modification_date(). Use HTTPCacheControlMiddleware::registerModificationDate() instead
  • Deprecated HTTP::register_modification_timestamp(). Use HTTPCacheControlMiddleware::registerModificationDate() instead
  • Deprecated HTTP::register_etag(). Use HTTPCacheControlMiddleware::ETagMiddleware() instead

Change log


  • 2018-04-23 d42bd6e File.allowed_extensions can have values removed via YAML configuration (Robbie Averill) - See ss-2018-014
  • 2018-04-23 30e2d9c Allow forced redirects to HTTPS for responses with basic authentication (Robbie Averill) - See ss-2018-009
  • 2018-04-10 0b7e665 Enable oembed to be disabled serverside (Damian Mooyman) - See ss-2018-003
  • 2018-04-10 7c2886d Update docs for oembed (Damian Mooyman) - See ss-2018-003
  • 2018-04-09 326b1ff Implement stronger oembed white/blacklist (Damian Mooyman) - See ss-2018-002

API changes

  • 2018-06-15 53dded8 Remove @internal from new 4.2 methods (Damian Mooyman)
  • 2018-06-12 ec956a6 Moving tests to use transactions (Daniel Hensby)
  • 2018-04-16 b1e8db1 Implement rollbackRecursive() / rollbackSingle() (Damian Mooyman)
  • 2018-04-16 c8b3593 Form::makeReadonly() returns self (Damian Mooyman)
  • 2018-04-06 6c616f5 Implement polymorphic sitetree link tracking (#2123) (Damian Mooyman)
  • 2018-03-22 7351caf Allow non-DataExtension Extensions to decorate dataobject (Damian Mooyman)
  • 2018-03-21 257ff69 Implement many_many through polymorphic (from only) (#7928) (Damian Mooyman)
  • 2018-03-21 32dcc4d add withVersionedMode() to safely isolate reading mode modifications (Damian Mooyman)
  • 2018-03-20 87afe84 Customise type names and operation names (#143) (Aaron Carlino)
  • 2018-03-05 3a1c813 Add getContentCSS() / setContentCSS() to allow per-config customisation of content_css (Damian Mooyman)
  • 2018-02-21 ced2ba1 Move CSV writing/reading to league/csv library (Daniel Hensby)
  • 2018-02-07 860fa2a Add excludeAny() and tests for complicated excludes/filters (#7838) (Andrew Aitken-Fincham)

Features and enhancements

  • 2018-06-18 95bcac7 Ensure test DB is flushed on either DDL or transaction-disabled tests (Damian Mooyman)
  • 2018-06-13 a88257e Add version to HTTPRequest and create raw string representation (Daniel Hensby)
  • 2018-05-21 865ebb3 Improve upgrading experience. (#8025) (Damian Mooyman)
  • 2018-05-20 1d34d19 Make FormAlert injectable (Robbie Averill)
  • 2018-05-17 e3237f9 Add revert mutation and refactor injector transformations (#2158) (Robbie Averill)
  • 2018-05-17 8ffa9dd Make Preview component injectable (#505) (Robbie Averill)
  • 2018-05-11 1a57c7c Add getJoinTable to MMTL (Daniel Hensby)
  • 2018-05-02 660e8bd static caching of schema types, as well as dynamic endpoint (Aaron Carlino)
  • 2018-05-01 aae318e Register fieldHolder HOCs with injector (Dylan Wagstaff)
  • 2018-04-27 e0b4d50 Add Loading indicator component, implement into FormBuilderLoader (#490) (Robbie Averill)
  • 2018-04-26 0494be7 Ensure that popover has correct container assigned (Damian Mooyman)
  • 2018-04-23 1b24bf6 Consolidate type / operation name generation (#151) (Damian Mooyman)
  • 2018-04-23 f50438e Ensure that default caches are segmented based on versioned state (Damian Mooyman)
  • 2018-04-19 7c3980a Refactor for more consistent use of union and inheritance types (#150) (Aaron Carlino)
  • 2018-04-11 4ddee82 Allow Preview class names to be overridden, and add i18n to messages (Robbie Averill)
  • 2018-04-11 c4f8af5 Add AbsoluteLink to history viewer page GraphQL query (#2142) (Robbie Averill)
  • 2018-04-10 0fa15f4 Ensure invalid stage values are throws as exceptions (Damian Mooyman)
  • 2018-04-09 19e45a9 Open modal default upload folder (#763) (Maxime Rainville)
  • 2018-04-04 2c266c2 Allow cleanupVersionedOrphans to be disabled (Damian Mooyman)
  • 2018-04-03 47bcac9 Add config var to skip confirm logout (#7977) (Andrew Aitken-Fincham)
  • 2018-04-02 14af3b8 Add --inverted modifier for Badge component with pattern library examples (Robbie Averill)
  • 2018-03-21 d88415b Decorate TestSession with stage params (Damian Mooyman)
  • 2018-03-21 26402f3 Enable request handlers to be extended (Damian Mooyman)
  • 2018-03-21 9a6d18a Set default reading mode in admin (disables stage=Stage rewrite links) (Damian Mooyman)
  • 2018-03-14 f51ea4d use scss variable than hard-coded color (#460) (Chris Joe)
  • 2018-03-12 8294ab3 Allow badge-pill class to be modified in Badge component (Robbie Averill)
  • 2018-03-12 79db975 add status badge to uploadfield item (Christopher Joe)
  • 2018-03-12 c92e5fe Ensure that publishSingle() updates local version (Damian Mooyman)
  • 2018-03-08 5db03d0 Add isLiveVersion and isLatestDraftVersion to Versioned and GraphQL DataObject scaffolding (Robbie Averill)
  • 2018-03-05 1a82f03 Add page GraphQL query HOC for history viewer component (Robbie Averill)
  • 2018-03-05 083308f Update table border colour to lighter grey (Robbie Averill)
  • 2018-02-28 4d424dd get_by_id: alternate signature to allow MyDataObject::get_by_id($id) (Damian Mooyman)
  • 2018-02-28 5735bee Upgrade to Bootstrap 4.0.0-stable and change to reactstrap 5.0.0-beta (#2101) (Luke Edwards)
  • 2018-02-28 62eb29e Upgrade to Bootstrap 4.0.0-stable and change to reactstrap 5.0.0-beta (#88) (Luke Edwards)
  • 2018-02-27 f181ba3 Upgrade to Bootstrap 4.0.0-stable and change to reactstrap 5.0.0-beta (#737) (Luke Edwards)
  • 2018-02-27 8094c26 Decouple preview from campaign admin (Damian Mooyman)
  • 2018-02-27 5825958 Upgrade to Bootstrap 4.0.0-stable and change to reactstrap 5.0.0-beta (#441) (Luke Edwards)
  • 2018-02-27 9474deb Add bulk insert feature for UploadField (Christopher Joe)
  • 2018-02-26 85dae1b Add warning when unpublishing owned files (#739) (Aaron Carlino)
  • 2018-02-26 c4e705a removed max width for content in intro screen (Christopher Joe)
  • 2018-02-25 1202807 Add warning for unpublishing owned records #444 (Aaron Carlino)
  • 2018-02-25 fe9f729 Add warning when unpublishing owned records (#122) (Aaron Carlino)
  • 2018-02-17 a214368 Add record count to dev/build output. (Sam Minnee)
  • 2018-02-15 de0b76d Fall back to SSViewer::get_themes when using themeResourceLoaders (Andrew Aitken-Fincham)
  • 2018-02-12 00ff3ba Make dropdownFieldThreshold configurable on DBForeignKey (#7789) (Andrew Aitken-Fincham)
  • 2018-02-09 0151449 remove File extension for backlink tracking in favour of UsedOnTable form field (Christopher Joe)
  • 2018-02-08 5f0a7cc add a Usage tab showing owners of files (Christopher Joe)
  • 2018-02-08 c370e3c Add a used-on table component for recorded ownerships (Christopher Joe)
  • 2018-02-07 dd82820 Allow GridFieldConfig::addComponents to accept an array (#7844) (Robbie Averill)
  • 2018-02-07 b084fe8 Convert page history notice to use Bootstrap 4 info alert (Robbie Averill)
  • 2017-11-30 9103816 Add php 7.2 support (Daniel Hensby)
  • 2017-09-26 2c121e8 approach (Daniel Hensby)


