Releases
0.4.8
Compare
Sorry, something went wrong.
No results found
Security and integrity
Added database integrity signing for protected rows with canonical payloads and derived HMAC keys.
Added file graph integrity checks before file content leaves the server through downloads, shares, WebDAV, HLS, archives, and previews.
Verified shared-folder ancestry before authorizing shared file access.
Report database tampering to admins both at read boundaries and when SaveChanges refuses to re-sign a tampered row.
Hardened session revocation after credential changes, password resets, refresh-token revocation, and passkey changes.
Encryption
Introduced the CTN2 encrypted stream format with authenticated terminator records and AAD-bound headers/file keys.
Added server/browser compatibility vectors and legacy encrypted stream read compatibility.
Previews and media
Fixed ffmpeg/ffprobe resolution in Docker by installing system binaries in the runtime image.
Bumped audio/video preview generator versions so files that failed with /app/ffmpeg are retried automatically.
Expanded source-code/text preview support and preview token validation.
Storage, WebDAV, and archives
Added deterministic stored ZIP archive downloads with UTF-8 paths, Content-Length support, and corrected ZIP64 metadata.
Added WebDAV quota properties for compatible clients.
Improved storage quota accounting, pressure handling, and backend telemetry probes.
UI and operations
Renamed hosted services to Cotton Bridge.
Expanded the security checkup with container and process hardening diagnostics.
Improved trash action visibility, drag previews, file preview behavior, and release/update notifications.
Added local performance benchmark tooling and baselines.
Refreshed README documentation.
Upgrade notes
This release adds database integrity and file graph integrity metadata. Existing rows are signed during the bridge upgrade window.
Operators should disable bridge mode after the upgrade window so missing or invalid signatures become hard failures.
Instances that previously hit the /app/ffmpeg preview failure will automatically retry audio/video previews after upgrade.
You can’t perform that action at this time.