Skip to content

Release 0.4.8

Choose a tag to compare

@github-actions github-actions released this 24 May 04:13
· 836 commits to main since this release

Security and integrity

  • Added database integrity signing for protected rows with canonical payloads and derived HMAC keys.
  • Added file graph integrity checks before file content leaves the server through downloads, shares, WebDAV, HLS, archives, and previews.
  • Verified shared-folder ancestry before authorizing shared file access.
  • Report database tampering to admins both at read boundaries and when SaveChanges refuses to re-sign a tampered row.
  • Hardened session revocation after credential changes, password resets, refresh-token revocation, and passkey changes.

Encryption

  • Introduced the CTN2 encrypted stream format with authenticated terminator records and AAD-bound headers/file keys.
  • Added server/browser compatibility vectors and legacy encrypted stream read compatibility.

Previews and media

  • Fixed ffmpeg/ffprobe resolution in Docker by installing system binaries in the runtime image.
  • Bumped audio/video preview generator versions so files that failed with /app/ffmpeg are retried automatically.
  • Expanded source-code/text preview support and preview token validation.

Storage, WebDAV, and archives

  • Added deterministic stored ZIP archive downloads with UTF-8 paths, Content-Length support, and corrected ZIP64 metadata.
  • Added WebDAV quota properties for compatible clients.
  • Improved storage quota accounting, pressure handling, and backend telemetry probes.

UI and operations

  • Renamed hosted services to Cotton Bridge.
  • Expanded the security checkup with container and process hardening diagnostics.
  • Improved trash action visibility, drag previews, file preview behavior, and release/update notifications.
  • Added local performance benchmark tooling and baselines.
  • Refreshed README documentation.

Upgrade notes

  • This release adds database integrity and file graph integrity metadata. Existing rows are signed during the bridge upgrade window.
  • Operators should disable bridge mode after the upgrade window so missing or invalid signatures become hard failures.
  • Instances that previously hit the /app/ffmpeg preview failure will automatically retry audio/video previews after upgrade.