AO3 News

Post Header

Published:
Mon, 10 Aug 2026 11:30:34 +0000
Tags:

In May, updates to AO3 focused on improving skins, collections, and gift exchanges, boosting performance across AO3, and addressing several security issues. The Collections page now has options to sort by number of works and bookmarks, and we've added some improvements to tag set nominations and the matching process for gift exchanges. The month also included multiple security fixes for permission issues, strengthened URL import protections, and updated dependencies.

Shoutout to this month's first-time contributors gemmie and Mane Muradyan, and special thanks to notpies and Taxen99 who alerted us to security issues.

Credits

  • Coders: Aya Sayadi, Bilka, cayugulan, Céline Bertau, gemmie, Hunter Ada Smith, Jesse Malark, Julian Saxl, kiyazz, Lara Rodrigues, Ling-Yi, Luis Pabon, Mane Muradyan, marcus8448, mjec, Nate Berkopec, nicolacleary, Noah Bravo, Pablo Monfort (VAIRIX), Pearl, Respheal, sarken, Scott Venkataraman, slavalamp, wAO3rker, Yang, zrei
  • Code reviewers: Bilka, Brian Austin, james_, Ling-Yi, marcus8448, redsummernight, sarken, slavalamp
  • Testers: Bilka, Berix, Brian Austin, choux, Claire P. Baker, LilyP, lydia-theda, marcus8448, Nary, ömer faruk, pk2317, sarken, slavalamp, therealmorticia

Details

0.9.474

On May 1, we released a bunch of miscellaneous bug fixes and updated the text on several pages.

  • [AO3-3601] - Deleting a pseud and choosing "Transfer these bookmarks to the default pseud" wouldn't reliably update the default pseud's bookmark index, so the bookmarks appeared to be gone. But they weren't! And now they should show up under the default pseud without a big delay.
  • [AO3-4693] - It was previously impossible to delete a collection that contained a challenge (such as a gift exchange or a prompt meme). Now you can delete your collection no matter what.
  • [AO3-6348] - In the tag autocomplete, a stray semicolon would sneak into tags with ampersands (&) if those tags also contained a pipe (|). That's fixed now!
  • [AO3-7267] - We now serve 404 Not Found errors to users and site admins if they try to access a preferences page for a user that doesn't exist.
  • [AO3-7316] - Shuffled some CSS around in the code for site banners. Neater now!
  • [AO3-7320] - We now make sure a comment won't be sent to our spam checker for evaluation if it's already considered spam.
  • [AO3-7331] - A user's Marked for Later page now displays their username in the browser page title.
  • [AO3-7337] - The "Sign-up closes:" time in a collection's blurb now adjusts to the timezone selected by a user in their preferences.
  • [AO3-7353] - When you're on your Refused Gifts page, the navigation buttons now indicate that this is indeed the page you're on, and Accepted Gifts are just a click away.
  • [AO3-7362] - Updated our takedown policy to add guidance related to requests made under the Take It Down Act (TIDA).
  • [AO3-7375] - JavaScript would break in browsers with localStorage disabled or not supported. Now it shouldn't throw up errors anymore!
  • [AO3-7376] - We now display a helpful message when you try to delete a pseud you have already deleted (e.g. in another tab), instead of throwing an Error 500.
  • [AO3-7405] - We improved the performance of generating the RSS feeds for tags.

0.9.475

Our May 12 deploy focused on collection and challenge improvements. On our Collections page, you can now sort all collections by the number of works or bookmarks they contain. \o/

  • [AO3-3764] - It was previously impossible to see all tag set nominations awaiting review. If there were too many to fit on one page, you'd have to review some first to make room. We have now added pagination buttons, so you can access all nominated tags!
  • [AO3-6068] - Some code cleanup.
  • [AO3-5764] - The notifications we send when someone submits a prompt fill contained very little information about the submitted work. We now include the same information as in subscription emails, so the prompter can review tags and warnings before opening the work.
  • [AO3-6106] - Checking the "Approve" ticky for a filled assignment in a moderated gift exchange will now correctly let the submitted work into the collection and mark the assignment as completed.
  • [AO3-6277] - If you run matching on gift exchange sign-ups and get no potential matches back, the notification email and matching page will now contain helpful information about the status of your matches, and what to do about it.
  • [AO3-6978] - In an effort to speed up a background process during work imports, we created a new table to store the original URLs of imported works. Making sure we aren't adding duplicates to AO3 should be much faster in the future!
  • [AO3-7012] - Gift works locked to registered users were hidden from site admins (such as Policy & Abuse volunteers) on gift pages or in gift searches. Now they show up.
  • [AO3-7179] - The success message you get when updating someone's membership status in a collection (such as making them an owner, or removing them as a member) now contains their pseud and username, as it should.
  • [AO3-7188] - You can now sort collections by the number of collected works or bookmarks!
  • [AO3-7239], [AO3-7392] - We prepared several help popups related to posting a work, as well as a line in work-related email notifications, for translation.
  • [AO3-7356] - We improved the performance and reduced the load on our database servers when displaying a series.
  • [AO3-7400] - The browser page title for a user's Gifts page is now correctly formatted.
  • [AO3-7411] - The browser page title for a work now lists both fandoms if the work contains two, and says "Multifandom" for works with three or more fandom tags.
  • [AO3-7415] - In a user's Preferences, the site skin options included skins that were just created as a parent for other skins and weren't actually supposed to be used by themselves. That's fixed now.
  • [AO3-7422] - We updated the erb gem update to address a security issue.

0.9.476

Our May 15 release focused on security issues.

  • [AO3-7385] - Under certain circumstances, it was possible to use the parent skin option to access the title and CSS of a site skin belonging to another user. It was not possible to look for skins belonging to a specific user. If a user included a name in skin titles or CSS (e.g., Darth Vader skin), that name would be visible, but it would not be possible to confirm whether that skin was created by a specific user. We are unable to verify that all or any skins were accessed in that manner.
  • [AO3-7420] - We fixed an issue that made it possible to use a POST request to reorder works in series you didn't own.
  • [AO3-7443] - We have removed Google from our list of permitted audio embed sources as they discontinued their audio player a long time ago.
  • [AO3-7433], [AO3-7438], [AO3-7439] - We updated some gems to address some security issues.

0.9.477

We deployed multiple improvements to skins, including allowing some new properties, on May 20.

  • [AO3-6390] - It's now only possible to change the default look of AO3 if you have database access (and not if you're merely logged in as a site admin).
  • [AO3-7160] - The username autocomplete when trying to assign a pinch hitter to an assignment will no longer be cut off after the first username.
  • [AO3-7189] - If a user applies a site skin containing broken code that renders the site unusable (and prevents them from accessing the option to revert to a different skin), a Support admin can now reset the skin in the user's Preferences.
  • [AO3-7345] - We have made the success message for temporarily setting a new site skin more informative.
  • [AO3-7388] - Since it's impossible to use a skin that's set to be a "Parent Only", it's also impossible to generate a preview of what AO3 would look like with that skin. We now display an error message if you try.
  • [AO3-7390] - We now allow the fill, stroke, and stroke-width CSS properties in work and site skins.
  • [AO3-6198], [AO3-6454] - We switched the code library for talking to our spamchecker to our own code, because the library was no longer maintained.
  • [AO3-7391] - We fixed some incorrect selectors in some rarely used CSS.
  • [AO3-7427] - We changed how we define some config variables to make things easier when using the Rails console.

0.9.478

On May 27, we turned on a setting to hopefully improve overall website performance.

  • [AO3-7465] - We enabled a Ruby setting which aims to improve performance of the whole site.
  • [AO3-7475] - We switched away from a GitHub Actions dependency that wasn't maintained.

0.9.479 & 0.9.481

On May 28 and May 31, we deployed security fixes for the work import form.

  • [AO3-7483], [AO3-7484] - When importing a work from a URL, some URL imports could bypass our proxy and access URLs within the internal AO3 network. We made sure they can't do that anymore.