Skip to content

v3.10.76

Choose a tag to compare

@andrevanzuydam andrevanzuydam released this 07 Apr 12:10

v3.10.76

Fixes

  • Middleware auth bypass — Write routes with custom middleware skip the built-in Bearer auth gate. Use @secured() / ->secure() / .secure to opt back in.
  • Dev admin SPA — Dynamic version label, XSS hardening, code block escaping.
  • Metrics drill-down — File detail endpoint works correctly on all server modes.

PHP-specific

  • Built-in socket server — Now populates $_COOKIE, $_GET, $_POST, $_SERVER before dispatch. Cookie-based OAuth sessions work under tina4 serve.
  • .htaccess — Removed forced HTTPS redirect (commented out, enable for production).
  • nginx.conf.example — New file with complete PHP-FPM config, security rules, auth header passthrough.
  • Version check — Fixed version_compare with mixed v-prefix Packagist versions.

Tests

  • 10 new Python tests, 8 new PHP tests for middleware auth bypass.