Skip to content

3.2.6-sr94.46: Safe dotted aliases

Choose a tag to compare

@RobinMJD RobinMJD released this 22 Sep 02:38
· 86 commits to main since this release

Safe Dotted Aliases

  • Use literal dotted aliases such as guide.pdf and docs/v2.release in personal, administrative, workspace and import workflows.
  • Reject reserved routes, traversal, ambiguous encoding, empty dot components and excessive length/depth consistently.
  • Preserve existing forwarding suffixes, alias retirement, domain scoping and legacy custom-alphabet compatibility. No migration or historical alias rewrite.
  • Fix MySQL stale-snapshot reservation races: ordinary and dotted aliases return controlled conflicts while preserving the winner and rolling back the loser.
  • Add real MySQL/PostgreSQL race and authorization tests, and 1440/390/320px browser checks for creation, editing, retained validation drafts and public redirects.

The full combined-source isolated regression passed. Release CI, exact homelab wrapper/security scan, recoverable backup and live acceptance remain separate deployment gates recorded in the community roadmap. No WAF/SSO changes; redirects remain public.