1.2.8
Fixed
- Fix fetching the IP for a user that could allow spoofing via headers. Vulnerability
IP Whitelist bypassreported by Paweł Hałdrzyński. - Ensure redirect param is validated to prevent malicious redirection. For custom forms, please update the redirect input to use
{{ redirect | hash }}otherwise logins will not work. VulnerabilityOpen-redirectreported by Paweł Hałdrzyński.