v1.3.0 Latest
New
- DRM can be turned on. Encrypted playback is an experimental preview: it appears as a protection level on a video only after you have chosen a packaging method, so a site that has not set one up cannot pick a level that would not protect anything.
Improve
- CSV exports of watch sessions and milestones are no longer capped. They previously stopped at 50,000 rows without saying so, which could hand someone an incomplete file believing it was whole.
- A user export that does hit its limit now says so in the file itself.
- CSV exports use less memory on large datasets. They loaded the whole result set before writing, despite describing themselves as streaming.
- Retired the [mediashield_upload] front-end shortcode. It never worked - five separate faults, including a required field with no selectable option that made the form impossible to submit on any site without a connected platform. Upload videos from Videos > Add New instead.
- Removed the email gate. It could never run on a default install: WordPress-gated videos deny logged-out visitors before the gate is reached, and on a members-only site the viewer is already identified, so the gate captured nothing the site did not already have.
- The "Require enrollment" setting now works as a master switch. It saved and was read by nothing, so turning it off did not open access and turning it on did not gate anything.
- Uploads now go to the destination set in Default Upload Target. The setting saved and every upload ignored it.
- Changing the default protection level now applies to videos you already have. Import and upload saved a copy of the default onto each video, which then outranked the setting forever.
- Removed the DRM packaging options that never did anything. "Local - Shaka Packager" and "AWS MediaConvert" appeared in the DRM Method list, and the Shaka Packager Path field and Auto-package toggle appeared below it, but no video was ever packaged by any of them. If your site had one of those methods selected, DRM Method now reads None, which is what it effectively was.
Fix
- A DRM-protected video now reaches the encrypted player. It was handed no playback address, so the encrypted player never started and the video played through the standard player unencrypted instead. Needs MediaShield 1.3.0.
- Revoking a viewer's DRM access now denies them a new license. Revocation was recorded and reported back to you, but the next license request minted a fresh one and handed over the content key, so revoking changed nothing.
- Videos uploaded to a connected platform now play. The video's address was saved as the temporary file path of the upload on your server for Vimeo, YouTube and Wistia, and as a playlist address Bunny refuses to serve unsigned for Bunny Stream, so an uploaded video never played on any of the four.
- Videos imported from Bunny Stream now play. Import saved the video's playlist address rather than its player address, and Bunny refuses unsigned playlist requests, so every imported video showed "403 Forbidden" in the player and none of them had ever played. Videos imported before this update are corrected automatically when you update.
- Connected platforms work again. Bunny Stream, Vimeo, YouTube and Wistia credentials were saved in one format and read back in another, so every connection reported itself as connected while no request using it could succeed.
- The plugin no longer fails to load from a fresh clone, which took the whole site down with it.
- Fresh installs now create the DRM licenses table. An inline comment inside the table definition made the statement fail silently, so new sites got every other table except this one and DRM license issuance could not work. Existing sites were unaffected.
- Deleting a video no longer deletes the original from Bunny, Vimeo, YouTube or Wistia. It is left in place so you can add it back whenever you want.
Security
- VPN detection no longer sends visitor IP addresses over an unencrypted connection. It now uses HTTPS and requires an API key, and stays off until one is entered.
- Shaka Packager is now run without a shell. The previous call was correctly escaped and not a vulnerability, but malware scanners match on the shape of the call, so customers could see their site flagged as compromised.
Dev
- Added the ms_vpn_api_key setting, with a field on the Alerts screen. The settings response reports only whether a key is set, never the key.
- Pro registers its DRM protection level through the new mediashield_protection_levels filter in MediaShield 1.3.0.
- Plugin::is_licensed() delegates to Licensing\License::is_valid(). The old inline check compared an array against the object the licensing SDK stores, so it could never return true.
- [mediashield_upload] stays registered as a stub that renders nothing for visitors. Deleting the handler would have printed the raw shortcode text on any page still carrying it.
- Removed the ms_email_captures table, the /email-gate/submit and /email-gate/test-webhook REST routes, the mediashield_pro_email_captured action, and the five ms_email_gate_* / ms_email_retention_months options.
- Collected email-gate leads are deleted on upgrade. Export them before updating if you still need them.
- Pro's test suite runs for the first time. It was pinned to a PHPUnit version the WordPress test suite cannot use, so every test failed before running.
- Deleted DRM\Packager and KeyServer::generate_key(). Packager had no callers anywhere in either plugin and generate_key() was called only from inside it, so ms_drm_keys could never be written. The mediashield_before_drm_package and mediashield_after_drm_package actions and the mediashield_pro_drm_package job are gone with it. KeyServer::get_key() and WidevineLicense remain - DRMController calls them.
Compat
- Requires MediaShield (free) 1.3.0. Install both updates together.