CoinForge Studio 1.5.1 — security hardening
Security hardening for the AI Assistant and the hosted app. Recommended update if you use the AI Assistant.
Hardening
- AI Assistant server: rejects non-loopback Host headers (blocks DNS-rebinding), compares its access token in constant time, and re-validates the export path so a design name can never write outside the exports folder.
- Hosted app & site: added standard security response headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, HSTS, Permissions-Policy).
- Account links: desktop-link records now self-expire so nothing lingers server-side.
No functional changes — same designer, same tools. See v1.5.0 notes for the AI Assistant itself.
Downloads
- CoinForgeStudio-Portable.exe - no install, no account, fully offline.
- CoinForgeStudio-Setup.exe - installer with shortcuts.
Windows SmartScreen: unsigned exe - More info -> Run anyway on first launch.