Skip to content

v1.0.6

Choose a tag to compare

@LifeIsHex LifeIsHex released this 28 Feb 22:11
· 13 commits to main since this release
  • CSRF protection enforced on all state-changing actions — delete, rename, new folder, copy, move, extract, compress now require POST + CSRF token
  • CSRF validation added to all AJAX endpoints — paste, delete-multiple, download-multiple, chmod now validate X-CSRF-Token header
  • XSS fix — escaped icon and permissions output in file listing template
  • XSS fix — escaped $assetsPath in all and <script> tag attributes
  • XSS fix — escaped $msg['type'] in CSS class output in layout and login templates
  • Open redirect fix — Response::redirect() now blocks absolute URLs and strips header injection characters
  • Header injection fix — PDF filename sanitized in Content-Disposition header
  • Action whitelist — unknown URL actions are now silently ignored instead of processed
  • Content-Security-Policy header added
  • Removed default credentials hint from login page
  • Disabled display_errors in entry point

Full Changelog: 1.0.5...1.0.6