Repository navigation
v3.6.0 — Stabilize & Harden
Summary
Structural reliability release. No new features. Every change closes a security gap, eliminates an inconsistency class, or removes duplication. E2E browser-tested across 5 parallel test suites (core pages, mobile/responsive, feeds/SEO, theme/dark mode, search/contact/errors).
Highlights
auth-fetch.jsmodule: single source of truth for mutation fetches — CSRF injection, auth error detection, structured JSON responses- Upload rate limiting: per-endpoint rate limit, environment-aware defaults
- CSRF enforcement: admin route group now has CSRF middleware at group level
- Content-negotiated errors: all middleware error paths return proper JSON or styled HTML
- Security fix:
renderHTMLno longer leaks server config (including credentials) in JSON error responses - SEO fix: duplicate meta tags eliminated across all public pages when SEO service is enabled
- Template fix:
html/templatetype error on canonical URL line no longer crashes page rendering
What Changed
Added
auth-fetch.jsmodule for centralized mutation fetches- Upload rate limiting (20 req/5min production)
abortWithErrormiddleware helper for content-negotiated errors
Changed
- CSRF enforcement at admin route group level
- JS fetch consolidation (removed 6 duplicate
getCSRFTokenimplementations) - CSS
--max-content-widthdesign token (replaces 14 hardcoded42remvalues) - CollectionPage JSON-LD consolidated to handler pattern
- Service worker cache version bumped to v5
Fixed
- Config leak in JSON error responses (critical security fix)
- Template crash from
html/templateandwith mixed types - Duplicate SEO meta tags across 9 per-page
-headtemplates - About page missing
og:descriptionandtwitter:description relativeTimeandtimeAgozero time guard- admin.js CSRF gap on POST requests
Full Changelog
See CHANGELOG.md for complete details.
Full Changelog: v3.5.0...v3.6.0