News

WebCalendar v1.9.24 Released: A Command Line, PHP 8.2, and What to Check Before Upgrading

WebCalendar v1.9.24 is out. It adds a command line tool for administrators, raises the minimum PHP version to 8.2, and repairs several features that had quietly stopped working, including Purge Events, which did not work at all. Three of the changes can affect an existing installation, so please read the next section before you upgrade.

Before You Upgrade

1. PHP 8.2 is now the minimum

PHP 8.1 reached end of life on 31 December 2025, and WebCalendar no longer supports it. The installation wizard now reports any PHP version below 8.2 as an error. Check your server’s PHP version before upgrading, especially on shared hosting where the default may lag behind. The official Docker images already run PHP 8.4.

2. Reminders triggered by URL will stop working

If you send email reminders by having something fetch tools/send_reminders.php over HTTP, that request now returns 403 Forbidden and your reminders will stop. Every script under tools/ is now command-line only. Older documentation offered the URL method for hosts without a PHP command line, which is why some sites use it.

You have two ways to fix it:

  • Use cron with the PHP CLI (preferred). cPanel, Plesk, and DirectAdmin all provide a cron facility that can run the PHP binary, even on shared hosting:
    */15 * * * * /usr/bin/php /path/to/webcalendar/tools/send_reminders.php
  • Use a reminder token. If your host offers no way to run a command at all, go to Admin > Settings > Email and click Generate New Token next to Reminder web trigger. Copy the token and URL right away because they are shown only once. The token is stored only as a hash, and every run triggered this way is written to the activity log.

3. Database failures now report failure

Previously, a fatal database error ended the script with exit status 0, which means “success.” For example, the reminder script could tell cron it had succeeded even when it never connected to the database. Fatal database errors now exit with status 1. That fix is intentional, but if you monitor WebCalendar’s cron jobs, a monitor that stayed green through a real fault may start alerting after you upgrade. That alert is a real problem that was previously hidden.

Upgrading

Back up your database, then run the installation wizard as usual. The Upgrade Guide has the details. The new command line tool can do both steps from a shell:

php bin/webcal.php db dump --output=backup.sql   # back up the webcal_* tables
php bin/webcal.php db check                      # exit 0 = up to date, 1 = upgrade pending, 2 = could not tell

This release includes one small schema change. Recurring events created through the MCP server were stored with the wrong event type. Nothing displayed incorrectly, but the upgrade fixes the stored value. It touches only recurring events and is safe to re-run.

New: A Command Line for Administrators

WebCalendar now includes bin/webcal.php, a single command line tool with thirteen commands. It reads the same configuration as the web pages, so it works against the installation it sits in without any database arguments. The most useful commands:

  • user reset-password --login=admin recovers a locked-out administrator. Passwords are stored as bcrypt hashes, so a hand-written SQL UPDATE can’t recover the account. The new password is generated and printed once, or you can pipe in one you choose. It is never accepted as a command-line argument, where ps and shell history would record it.
  • diagnose prints an environment report to attach to a bug report: WebCalendar and PHP versions, extensions, database type, and writable directories. It includes no passwords, tokens, host names, or email addresses, and it runs even on a broken installation.
  • db check and db dump tell you whether an upgrade is pending and back up only the webcal_* tables, using the credentials from your existing configuration.
  • config list / get / set read and change system settings, which helps when a setting is what keeps you out of Admin > Settings.
  • email test --to=ADDRESS sends one message and shows the mail server’s own error if it’s rejected, so you can tell whether the problem is in WebCalendar or the mail server.
  • export / import use the same code as the Export and Import pages. user list, reminders send, and remotes refresh complete the set.

Run it as a user who can read includes/settings.php, and run commands that write files as the web server user. The full reference is in docs/cli.md.

Repaired

  • Purge Events works. It had never worked: its Delete button had no value attribute, so browsers never submitted it. Fixing that exposed more problems. The purge read the wrong date fields, ignored “Purge deleted only” when All users was selected, reported misleading row counts, and labeled a completed purge as a preview. All of these are fixed.
  • Event approval emails include the full calendar attachment again. A single = where == was meant caused an unrelated request parameter to filter exports down to public events. Approving an event could therefore send an ICS attachment with non-public events missing.
  • “Include deleted entries” on the Export page now does something.
  • One unreachable remote calendar no longer stops the others from refreshing.
  • The login page is properly centered, and its labels are correctly associated with their inputs for screen readers.
  • The install test scripts no longer delete a live installation’s configuration. They now refuse to run when includes/settings.php exists unless you explicitly allow it.

Documentation

The troubleshooting guide’s answer to “I can’t log in” used to be an SQL statement that stored an unsalted MD5 password hash. It now points to user reset-password. The MCP documentation now covers all nine tools instead of four. MCP_WRITE_ACCESS, the setting that controls whether an AI assistant can change your calendar (off by default), is now documented in the configuration reference and security guide as well as the MCP page. New tests keep the documented version numbers and tool list in sync with the code.

Also in v1.9.23

If you are coming from v1.9.22, you also get the August maintenance release, v1.9.23:

  • The Month/Week/Year date selectors appear again on sites that disable the top menu, and the Admin “Date Selectors position” setting works again. Both had been broken since v1.9.0.
  • The Export for WordPress page is now reachable from the Admin Settings menu, including on sites that disable the trailer.
  • The English translation is now 100% complete, and three phrases that could never be translated in any language have been fixed.

Get It

Download the release ZIP from GitHub, or pull the Docker image, which is available for amd64 and arm64:

docker pull craigk5n/webcalendar:1.9.24

Every release is signed. The ZIP contains a manifest with a SHA-256 hash for every file, signed with Ed25519, and the archive itself has a separate Sigstore signature. You can verify either one without trusting the download server. See docs/release-signing.md for instructions.

New to WebCalendar? The quickest way to try it is our Docker Compose guide. The full list of changes, with the reasoning behind each one, is in the changelog. Bug reports and questions are welcome on GitHub.

Leave a Reply

Your email address will not be published. Required fields are marked *