MediaClean 0.1.6 security patch.
Fixes:
- Reject non-loopback
Hostheaders and cross-origin writes on the local server, closing a DNS-rebinding / CSRF path where a visited web page could drive scan / quarantine / purge against your files._is_loopback_hostwas previously only checked at bind time, never per request. - Plural-agreement fix in the keeper reason ("2 other copy looks like…" → "2 other copies look like…").
Verification:
- pytest: 19 passed (new end-to-end guard test for rebound reads/writes and cross-origin writes)
- Developer ID signed, Apple-notarized, stapled, and Gatekeeper accepted
SHA-256: 2bf6af486566eca1365864a4d6b5ea9a3636ef8ca3022088d206009559ad08ab