Release v1.4.8
Release v1.4.8
Changelog
Fixed
- Consent modal JS: prepare Symfony SameOrigin CSRF (double-submit cookie +
csrf-tokenheader) before XHR so hosts can keepcsrf_protection: truewithout relying on nativesubmit/ Stimulus.
Documentation
- SECURITY.md, USAGE.md, CONFIGURATION.md — document XHR CSRF double-submit path
Full Changelog: v1.4.7...v1.4.8