Changelog
Security
- [a7be68] security: 10-slot Semaphore around password hash functions to prevent resource exhaustion attacks
- [6dfffd] security: 10-slot Semaphore around password hash functions to prevent… (#904)
- [24cced] security: IDOR on ExecutionStatus API
- [03da2f] security: Try to set cookies secure, with force override option
Bug fixes
- [cb71dd] fix: Set common security headers by default
- [894f3d] fix: Set common security headers by default (#903)
- [4af4d5] fix: ShowDiagnostics now behind policy checks
- [54eb2a] fix: User login log message fixed when password matches, but user lookup fails
Others
- [2eb5f0] Next (#905)
- [f3549b] Remove dead CORS package (L-2)
- [e48728] doc: Updated agents codestyle
Container images (from GitHub)
docker pull ghcr.io/olivetin/olivetin:3000.10.2
Container images (on Docker Hub)
docker pull docker.io/jamesread/olivetin:3000.10.2
Upgrade warnings, or breaking changes
- No such issues between the last release and this version.
Useful links
Thanks for your interest in OliveTin!