Amfora 1.0.0
Amfora 1.0.0 combines the unified website, login and transfer design with the security fixes from the release audit.
- Protected share downloads, uploads bound to server authorization and atomic upload quotas.
- Password verification challenges for 2FA, protected remembered device tokens and provider management restricted to administrators.
- Canonical reset links, escaped mail templates and explicit proxy trust.
- Updated production dependencies: zero known vulnerabilities in both JavaScript package audits.
Validation: 68 automated tests, isolated security regressions, a real 101 MiB multipart transfer, concurrent quota checks, local SMTP delivery, and desktop/mobile browser checks. See the attached validation summary and release/upgrade notes for scope and configuration requirements.
Back up application data before upgrading. Set APP_URL to the actual application origin. Existing remembered devices must authenticate again.