Skip to content

V3.4.6

Choose a tag to compare

@52Lxcloud 52Lxcloud released this 06 Feb 03:22
· 12 commits to master since this release
4fc956c

CaThis release contains critical security updates; please update as soon as possible.
Updating to this version will cause the following unavoidable side effects:

All active login sessions will be invalidated;
Existing direct links for non-redirected local storage policies will become invalid (URLs containing ?sign=xxx);
Other signed temporary links that have not yet expired will become invalid (URLs containing ?sign=xxx).
If your database was first initialized with Cloudreve version >= 4.10.0, this security vulnerability does not affect you.
Specific details will be disclosed 60 days after this release.
Fix: Use cryptographically secure random number generator for sensitive fields (Kudos to @orenyomtov)
Improvement: File list tooltips should no longer obstruct downward mouse movement (cloudreve/cloudreve#3170)
Improvement: Performance optimization for drag-selection of files
Fix: Unable to drag and drop files in list view (cloudreve/cloudreve#2937)
Fix: Inaccessible direct links for newly created empty files (cloudreve/cloudreve#3239)
Fix: 500 error when uploading to SeaweedFS S3 storage policies (cloudreve/cloudreve#3265)
Fix: OAuth endpoint handling of code_challenge inconsistent with documentation (cloudreve/cloudreve#3261)