Skip to content

Version 0.8.3

Latest

Choose a tag to compare

@tanftw tanftw released this 01 Oct 04:57
149d7c1

What's changed

  • Fix Accordion and Collapsible sizing, animation, and accessibility. Open content can grow and show pop-out controls without clipping.
  • Harden RPC, upload, SSE, and WebSocket authorization and origin checks. Isolate each WebSocket action's authenticated identity.
  • Strengthen session expiration and rotation, OAuth account linking, one-time authentication tokens, and password reset handling.
  • Improve server-only code removal from browser bundles and prevent static file access outside configured roots.
  • Fix rendering, CLI scaffolding, migration error handling, and framework installation issues. Add view transition options and full-screen Sheet support.
  • Update dependencies, regression tests, package type checks, and documentation.
  • Set all repository package manifests to version 0.8.3.

Upgrade notes

  • WebSocket actions must read the authenticated user from this.user or this.c.get('user'). The framework no longer appends a user argument.
  • Custom session stores must implement has(id) and must not recreate expired or destroyed sessions during writes.
  • Applications that copied generated authentication code should adopt the updated token consumption, password reset, and OAuth linking behavior. See the authentication, session, and OAuth guides.

The dependency audit found no production advisories. Three development-only advisories remain in Electron packaging dependencies (extract-zip and image-size).

Full changelog: 0.8.2...0.8.3