MediaTranscribe 0.1.4 security patch.
Fixes:
- Reject non-loopback
Hostheaders and cross-origin writes on the local server, closing a DNS-rebinding / CSRF path where a visited web page could drive transcription, transcript edit/delete, or export-to-folder against your machine. The loopback check was previously only applied to the bind host, never to incoming requests.
Validation:
- pytest: 16 passed (new end-to-end guard test for rebound reads/writes and cross-origin writes)
- Developer ID signed, Apple-notarized, stapled, and Gatekeeper accepted (app + DMG)
SHA256: ef08bab5a1ed91391cbe0d42f7a443f4185fffa95087bf755cf9e2d34154b755