This release includes an important security fix. Inbox code for axum was missing hash validation for the request body. This means an attacker could take a valid signed request from actor X, swap in any body and it is accepted as coming from X. Big thanks to @limeburst for reporting this!
The patch also fixes a potential denial of service attack, as the axum handler was reading HTTP request bodies with unlimited size.
If you are using activitypub_federation in production with axum, upgrade to the new version immediately. activitypub_federation with actix-web is not affected, and there is no need to upgrade.
What's Changed
Full Changelog: 0.6.5...0.6.6