Skip to content

v4.0.3

Compare
Choose a tag to compare
@zerocrates zerocrates released this 04 Aug 17:11
· 476 commits to develop since this release

Bugs Fixed

  • Malformed/malicious non-image files could improperly be allowed as uploaded assets
  • Installation title was not properly escaped when displayed in several views
  • The accept attribute for the upload input for assets was not updated to match the new default allowed asset types

Changes

  • Uploaded assets are now checked for both type and extension
  • Alongside the configurable list of allowed asset types introduced in 4.0.2, there is now a configurable list of allowed asset file extensions