Repository navigation
v0.6.1
###v0.6.1 (2026-05-30)
- Security (main):
main-state.phpno longer emits the per-boot CSRF token in its read-only JSON snapshot. The token is delivered solely via the#modernui-main-rootdata-csrf attribute (htmlspecialchars-escaped), which the front-end already treats as authoritative — keeping it out of a readable response body (data minimization / defense-in-depth). No functional change: action POSTs still read the token from the attribute. - Fix (main): Unassigned Devices "Historical (previous) devices" detection now compares serials exactly instead of with a loose bidirectional substring test. A previously-seen device whose serial happens to be a substring of an attached disk's serial (or vice-versa) is no longer wrongly treated as present and hidden from the Historical list.