# 25.02.1 release candidate

**URL:** <https://forums.ankiweb.net/t/25-02-1-release-candidate/59180>\
**Category:** Beta Testing\
**Created:** [April 17, 2025, 3:08am UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180 "2025-04-17T03:08:47Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![dae](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/dae/32/65_2.png) [@dae](https://forums.ankiweb.net/u/dae)\
**Post date:** [April 17, 2025, 3:08am UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/1 "2025-04-17T03:08:47Z")

</div>

Hi all,

I’d appreciate it if you could give this security fix a quick test. If it doesn’t introduce significant regressions, I hope to release it tomorrow.

> **[Release 25.02.1 · ankitects/anki](https://github.com/ankitects/anki/releases/tag/25.02.1)**
>
> This is a security-focused update. If you use any shared decks, updating is strongly recommended.
> 
> The review screen had protections in place to prevent shared decks from accessing other data on yo...

---

<div class="post-metadata">

**Author:** ![Anon\_0000](https://avatars.discourse-cdn.com/v4/letter/a/c67d28/32.png) [@Anon\_0000](https://forums.ankiweb.net/u/Anon_0000)\
**Post date:** [April 17, 2025, 11:43am UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/2 "2025-04-17T11:43:55Z")

</div>

FYI:  
@llama found something and opened a PR:

> <https://github.com/ankitects/anki/pull/3928>
>
> There's a slight visual regression (sorry!) after #3925 whereby the aforemention…ed dialogs flash more(?) after opening
> 
> \`AnkiWebView.set\_kind\` now potentially \[sets\](https://github.com/ankitects/anki/blob/1a68c9f5d5bcc197b641fe7405e5d9a4823928f3/qt/aqt/webview.py#L401) a new page, ~~and it flashes despite setting its background colour \[immediately after\](https://github.com/ankitects/anki/blob/1a68c9f5d5bcc197b641fe7405e5d9a4823928f3/qt/aqt/webview.py#L365)~~. \`set\_kind\` needs to be called for those dialogs because their forms are codegen'd from qt ui designer files, which, as far as i can tell from the \[schema\](https://doc.qt.io/qt-6.9/designer-ui-file-format.html), don't seem to allow passing in custom arguments directly to widget constructors
> 
> ~~The fix proposed here is to replace the webview widgets in those ui files with subclasses that have the correct kind filled in, to avoid calling \`set\_kind\` after init~~
> 
> ~~After this, only the legacy deck stats would still call it (and use the hack in \`set\_kind\`), as it shares the same form (and webview widget) with the "new" deck stats~~
> 
> EDIT: I've overthought this by overlooking that the page's background colour wasn't set again after \`set\_kind\` sets a new page, adding it seems to have gotten rid of the flashes

---

<div class="post-metadata">

**Author:** ![dae](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/dae/32/65_2.png) [@dae](https://forums.ankiweb.net/u/dae)\
**Post date:** [April 17, 2025, 2:33pm UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/3 "2025-04-17T14:33:19Z")

</div>

I’ve uploaded a new build to the same location that includes the fix above, and marked it as stable.

---

<div class="post-metadata">

**Author:** ![kohei](https://avatars.discourse-cdn.com/v4/letter/k/47e85d/32.png) [@kohei](https://forums.ankiweb.net/u/kohei)\
**Post date:** [April 18, 2025, 4:06am UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/4 "2025-04-18T04:06:31Z")

</div>

After updating to 25.02.1, any `<a onclick="…">` inside the static card‑template HTML no longer fires, even though the release notes only mention stripping `onclick` from _field content_.

Is this an intentional security change or a regression? If intentional, what’s the supported way to attach click handlers from the template—`addEventListener` in a `<script>` after render, or something else?

---

<div class="post-metadata">

**Author:** ![dae](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/dae/32/65_2.png) [@dae](https://forums.ankiweb.net/u/dae)\
**Post date:** [April 18, 2025, 4:21am UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/5 "2025-04-18T04:21:38Z")

</div>

`<a onclick='alert(1)'>` works for me inside a card template. The change in 25.02.1 should only affects JS references inside individual fields in the editor. Please break the problem you’re having into a minimum reproducible example, and I’ll look into it.

---

<div class="post-metadata">

**Author:** ![kohei](https://avatars.discourse-cdn.com/v4/letter/k/47e85d/32.png) [@kohei](https://forums.ankiweb.net/u/kohei)\
**Post date:** [April 18, 2025, 4:47am UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/6 "2025-04-18T04:47:46Z")

</div>

Hi Dae,

Figured it out—onclick itself was never the problem.

The click was being swallowed because the link had target=“\_blank”.

In 25.02.1 the set\_open\_links\_externally(true) code now intercepts every \_blank click in the capture phase and calls preventDefault()/stopPropagation(), so my inline onclick never had a chance to run.

Removing \_blank (or opening the window manually inside the handler), or moving the handler to addEventListener(‘click’, …, true) fixes it. So no regression on your side—just my template colliding with the new security hook.

Thanks for the quick help.

---

<div class="post-metadata">

**Author:** ![DerIshmaelite](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/derishmaelite/32/17983_2.png) [@DerIshmaelite](https://forums.ankiweb.net/u/DerIshmaelite)\
**Post date:** [April 18, 2025, 12:27pm UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/7 "2025-04-18T12:27:31Z")

</div>

I am getting this message now 🙁 What has happened ❓ My collection is already huge and will continue to get bigger. I cannot split it up because I have to review all of my cards. How do I reverse this ❓ Now I cannot sync anymore and this has stopped my workflow…

 ![image](https://us1.discourse-cdn.com/flex002/uploads/anki2/original/3X/8/d/8df27979899889e48680a0d31fbb4a8df8c03687.png)

---

<div class="post-metadata">

**Author:** ![Keks](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/keks/32/20537_2.png) [@Keks](https://forums.ankiweb.net/u/Keks)\
**Post date:** [April 18, 2025, 12:52pm UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/8 "2025-04-18T12:52:34Z")

</div>

# [Are there limits on file sizes on AnkiWeb?](https://faqs.ankiweb.net/are-there-limits-on-file-sizes-on-ankiweb.html#are-there-limits-on-file-sizes-on-ankiweb)

---

<div class="post-metadata">

**Author:** ![DerIshmaelite](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/derishmaelite/32/17983_2.png) [@DerIshmaelite](https://forums.ankiweb.net/u/DerIshmaelite)\
**Post date:** [April 18, 2025, 12:58pm UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/9 "2025-04-18T12:58:28Z")

</div>

Damn. I have exported a large deck of mine which I do not use at all. It has freed up space, but eventually I will be having this problem again in the future, as I am reviewing all of my collection as a whole.

I take it, I can still use my collection but without syncing it would be in danger of data loss ❓

What if I would want to use Anki where I left off on a new device. ❓Or if I wanted to backup my Anki ❓

Is there something I could tweak here ❓

 ![image](https://us1.discourse-cdn.com/flex002/uploads/anki2/original/3X/f/5/f53a0f8e91818ed2888d7710781ec9d75aa2f0c2.png)

Now every time I try to sync, it shows me this message

 ![image](https://us1.discourse-cdn.com/flex002/uploads/anki2/original/3X/0/5/0520a982bb7e95e147503b6322a93ba391e9484c.png)

I press upload to Ankiweb, it syncs. The next time I close Anki, it shows me this message again.

---

<div class="post-metadata">

**Author:** ![sorata](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/sorata/32/34115_2.png) [@sorata](https://forums.ankiweb.net/u/sorata)\
**Post date:** [April 18, 2025, 1:07pm UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/10 "2025-04-18T13:07:33Z")

</div>

There is the option of deleting revlogs of cards that Anki stores or deleting whole cards. Nothing you can do with the setting.

If you’re comfortable with a custom sync server, maybe it’s worth checking that out too. (I suggest we continue this in a different thread if you want to).

---

<div class="post-metadata">

**Author:** ![aleks\_ya](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/aleks_ya/32/22205_2.png) [@aleks\_ya](https://forums.ankiweb.net/u/aleks_ya)\
**Post date:** [April 18, 2025, 1:15pm UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/11 "2025-04-18T13:15:20Z")

</div>

[Note Size](https://ankiweb.net/shared/info/1188705668) addon can help you to identify huge notes and reduce collection size

---

<div class="post-metadata">

**Author:** ![DerIshmaelite](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/derishmaelite/32/17983_2.png) [@DerIshmaelite](https://forums.ankiweb.net/u/DerIshmaelite)\
**Post date:** [April 18, 2025, 1:16pm UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/12 "2025-04-18T13:16:12Z")

</div>

I have moved this discussion over to this topic now

> [@Apparently reached Collection Size limit. What now?](https://forums.ankiweb.net/t/apparently-reached-collection-size-limit-what-now/59265):
>
> Continuation of this discussion

---

<div class="post-metadata">

**Author:** ![Eltaurus](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/eltaurus/32/10287_2.png) [@Eltaurus](https://forums.ankiweb.net/u/Eltaurus)\
**Post date:** [April 20, 2025, 1:18pm UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/13 "2025-04-20T13:18:16Z")

</div>

It would be nice if instead of simply stripping unsafe attributes from html tags the update would transfer their values to something innocuous, for example:  
`onclick="somefunction()"` → `data-onclick="somefunction()"`  
`part="..."` → `data-part="..."`  
Especially since the sanitization happens silently, with no immediate indication. The suggested modification will still prevent things relying on the old attributes from working (as expected from a security update) but at least all information will be preserved and potentially salvageable.

As an example use case, I relied on this addon to make cross-references between cards:  
[https://github.com/Arthur-Milchior/anki-link-to-open-browser](https://github.com/Arthur-Milchior/anki-link-to-open-browser)  
What’s important is that it stores nid of a card being referenced as a function argument inside onclick. Were I not to notice the change in time and revert to the previous Anki version, this update would wipe the key information about almost 100k links, that were manually created one by one over the years, without any warning and with no easy way of restoring it.

---

<div class="post-metadata">

**Author:** ![jcznk](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/jcznk/32/15215_2.png) [@jcznk](https://forums.ankiweb.net/u/jcznk)\
**Post date:** [April 21, 2025, 1:06pm UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/14 "2025-04-21T13:06:28Z")

</div>

It looks like the new field sanitizer is stripping links that don’t start with `http://` or `https://` ? This breaks custom protocol links used to open local files in other software.

For example:

```auto

<a href="zotero://select/library/items/RGIKTJSR">Open Zotero</a>

```

is automatically converted to:

```auto

<a>Open Zotero</a>

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex002/uploads/anki2/original/1X/8f1279ababc5879d54e4838989f606cfe55af8c7.jpeg) [@system](https://forums.ankiweb.net/u/system)\
**Post date:** [May 21, 2025, 1:07pm UTC](https://forums.ankiweb.net/t/25-02-1-release-candidate/59180/15 "2025-05-21T13:07:14Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
