Releases
v8.4
Compare
Sorry, something went wrong.
No results found
feat(mobile): add Apple, Google, and Facebook authentication
fix(security): unrestricted file uploads and renames (#98 )
fix(security): prevent directory traversal in file delete routes (#98 )
fix(security): prevent directory traversal in file rename routes (#98 )
fix(security): unauthenticated admin registration (#99 )
fix(security): move route authentication to dedicated middlewares (#99 )
fix(security): verify Google, Facebook, and Apple tokens cryptographically in backend (#99 )
fix(security): systemic cross-supplier IDOR and unauthenticated admin registration (#99 )
fix(sercurity): prevent non admin users from modifying user roles (#99 )
fix(security): prevent non admin users from modifying other users' language (#99 )
fix(security): restrict change password page to authorized users only (#99 )
fix(security): restrict fetching users to admin and supplier only (#99 )
fix(security): restrict location update and delete operations to authorized users only
fix(security): restrict car update and delete operations to authorized users only
fix(security): get booking route not protected by auth middleware
fix(admin): birthDate field not set initially in update user form
fix(admin): supplier full name validation not working
chore(deps): update dependencies
You can’t perform that action at this time.