v1.0.6
- CSRF protection enforced on all state-changing actions — delete, rename, new folder, copy, move, extract, compress now require POST + CSRF token
- CSRF validation added to all AJAX endpoints — paste, delete-multiple, download-multiple, chmod now validate X-CSRF-Token header
- XSS fix — escaped icon and permissions output in file listing template
- XSS fix — escaped $assetsPath in all and <script> tag attributes
- XSS fix — escaped $msg['type'] in CSS class output in layout and login templates
- Open redirect fix — Response::redirect() now blocks absolute URLs and strips header injection characters
- Header injection fix — PDF filename sanitized in Content-Disposition header
- Action whitelist — unknown URL actions are now silently ignored instead of processed
- Content-Security-Policy header added
- Removed default credentials hint from login page
- Disabled display_errors in entry point
Full Changelog: 1.0.5...1.0.6