Skip to content

v3.0.0-alpha.4

Latest

Choose a tag to compare

@ajitbohra ajitbohra released this 09 Sep 07:30

🔒 Security

  • API: Prevented subscription_fee mutation on invoice updates to fix a business-logic bypass vulnerability that allowed wiping member balances without recording payments.
  • Access Control: Prevented inactive users from authenticating and accessing the application panel.
  • Access Control: Prevented privilege escalation vulnerabilities during user role assignments.

🧹 Maintenance & Chores

  • Testing: Adjusted test configuration settings to skip vite.

Full Changelog: v3.0.0-alpha.3...v3.0.0-alpha.4