Skip to content

v2.5.1

Latest

Choose a tag to compare

@PortableProgrammer PortableProgrammer released this 28 May 15:42
· 3 commits to main since this release
v2.5.1
426d4b6

Patch release: security hardening, bug fixes, dependency pinning, and CI cleanup.

Security

  • SQL injection — set-pref route hardened via static column lookup map (was interpolating user-controlled column names).
  • Authorization tightening — delete-invite upgraded from authenticateToken to admin-only.
  • Open redirect — login redirect parameter now validated as a relative path before use.
  • Error-detail leak — authenticateAdmin catch block no longer surfaces internal error specifics.

Bug fixes

  • Dashboard delete-user link was passing the current user's id/username instead of the target row's — data-loss-class bug.
  • Implicit global — missing const on response in comments and single-comment-thread routes.
  • PRAGMA foriegn_keys typo in lazy-delete-sessions migration — SQLite silently ignored it, so FK enforcement wasn't actually active during that migration.

Dependencies

  • @types/bun: latest → ^1.3.0
  • Dockerfile base: oven/bun:latest → oven/bun:1

Internal

  • CI workflow: removed dead dev branch logic from publish-docker.yml. The dev branch is being retired in favor of GitHub Flow (feature branches → main via PR). Also fixes a latent bash syntax error in the removed block.

Full changelog: v2.5.0...v2.5.1