Skip to content

Slink 1.0.2

Latest

Choose a tag to compare

@pardel pardel released this 28 Sep 20:28

A security and reliability release. Upgrading is recommended: it closes a cross-site request forgery hole in the admin API.

Security

  • Cross-site requests are refused. Cloudflare Access signs you in with a cookie the browser also sends when another site triggers the request, so a malicious page could archive, edit or create links on your behalf. Every POST, PATCH and DELETE on /api/* must now carry an Origin header matching the admin host, or it gets a 403. The dashboard is unaffected; a script calling the API must now set Origin itself.

Fixed

  • Deleting a link can no longer lose its analytics. The clicks and the link are removed in one transaction; before, a failure between the two statements left the link with its clicks gone.
  • HEAD requests no longer count as clicks. Link checkers and crawlers get the redirect without inflating the numbers.
  • A null or non-object JSON body gets a 400 instead of a 500.
  • Account-wide analytics no longer scan every click. A new index on click timestamps (migration 0004) serves them and the daily retention prune, saving D1 reads on the free tier.
  • The dashboard can't show stale or wrong data after a save. Late list responses are dropped instead of reverting a change, a renamed link resolves at its new URL straight away, and a failed refresh shows a Retry banner.
  • Short links and QR codes always use the public host. The dashboard waits for its settings (with Retry on failure) instead of falling back to the admin address.
  • The actions menu works everywhere. It no longer hides behind the next card, flips above its button near the bottom of the screen, closes on outside clicks, and is keyboard navigable (focus moves into it; arrows, Home/End, Escape and Tab behave as expected).
  • Malformed URLs such as /links/% show "No link found" instead of a blank dashboard.
  • README: the Develop steps create wrangler.jsonc before migrating, and the Deploy step uses npm run deploy, which builds the dashboard first.

Upgrading

Use Node 22, then:

npm ci
npm run db:migrate:remote   # adds the clicks timestamp index
npm run deploy