github DRYTRIX/TimeTracker dev-dev-23-9b7aa3a9
Development Build dev-23-9b7aa3a9

latest releases: v4.23.1, v4.23.0, v4.22.2...
pre-release5 months ago

Development Build

**Version:** dev-23-9b7aa3a9
**Commit:** 9b7aa3a
**Branch:** develop
**Build:** #23

### Docker Image
```
ghcr.io/DRYTRIX/TimeTracker:develop
```

### Quick Start
```bash
docker pull ghcr.io/DRYTRIX/TimeTracker:develop
docker-compose -f deployment-dev.yml up -d
```

### Changes
security: Add CSRF token protection to all POST forms" -m " Complete CSRF protection implementation across the entire application. Fixed 31 HTML forms and 4 JavaScript dynamic form generators that were missing CSRF tokens.

Affected modules: Projects, Clients, Tasks, Invoices, Comments, Admin, Search

  • All HTML forms now include csrf_token hidden input
  • JavaScript forms retrieve token from meta tag in base.html
  • API endpoints properly exempted for JSON operations
  • 58 POST forms + 4 dynamic JS forms now protected

Security impact: HIGH - Closes critical CSRF vulnerability
Files modified: 20 templates

---
*This is an automated development build. Use at your own risk.*

Don't miss a new TimeTracker release

NewReleases is sending notifications on new releases.