Added
- Fixed footer with current version and automatic update check
- Local self-hosted fonts for improved privacy and independence from Google Fonts
Changed
fqdnUrlnow defaults bare hostnames tohttps://...
Security
- Fixed client-side XSS risk in
customTextby sanitizing supported HTML before rendering - Blocked unsafe URL schemes in
fqdnUrl - Added a CSP for browser-side hardening
- Reduced metadata leakage on remote requests with stricter referrer handling
- Changed imported external icon/image behavior to avoid automatic remote loading. Click "LINK" after import to re-enable loading.
- Added 1 MB limits for imported settings, uploaded SVGs, and fetched SVGs, which is in line with the limits inside Proxmox