- Prevent Host header injection attacks on the password recovery endpoint. A new setting
commafeed.password-recovery-public-base-urlhas been added to specify the base URL to use in password recovery emails. This setting is only required when the password recovery feature is enabled, which is not the default.