Repository navigation
Patch release: security hardening, bug fixes, dependency pinning, and CI cleanup.
Security
- SQL injection —
set-prefroute hardened via static column lookup map (was interpolating user-controlled column names). - Authorization tightening —
delete-inviteupgraded fromauthenticateTokento admin-only. - Open redirect — login
redirectparameter now validated as a relative path before use. - Error-detail leak —
authenticateAdmincatch block no longer surfaces internal error specifics.
Bug fixes
- Dashboard delete-user link was passing the current user's id/username instead of the target row's — data-loss-class bug.
- Implicit global — missing
constonresponseincommentsandsingle-comment-threadroutes. PRAGMA foriegn_keystypo in lazy-delete-sessions migration — SQLite silently ignored it, so FK enforcement wasn't actually active during that migration.
Dependencies
@types/bun:latest→^1.3.0- Dockerfile base:
oven/bun:latest→oven/bun:1
Internal
- CI workflow: removed dead
devbranch logic frompublish-docker.yml. Thedevbranch is being retired in favor of GitHub Flow (feature branches →mainvia PR). Also fixes a latent bash syntax error in the removed block.
Full changelog: v2.5.0...v2.5.1