github PicPeak/picpeak v3.131.4-beta.0

pre-release2 hours ago

3.131.4-beta.0 (2026-09-11)

Bug Fixes

  • backend: bump sharp, nodemailer, multer, js-yaml, joi for security fixes (#1374) (f6b81fa)
  • backend: contain and sanitize the SQLite restore source path (#1384) (316bcbd)
  • backend: enforce event ownership on short URL deletion (#1379) (e290207)
  • backend: reject a replayed TOTP code within its validity window (#1389) (cdde937)
  • backend: require actor to hold every permission of a role they grant (#1378) (59ea83c)
  • backend: shorten payment-check token TTL and notify admin on use (#1385) (e324791)
  • backend: use the strong password generator for resets and enforce must_change_password (#1387) (b798d8e)
  • backend: validate business-profile logo uploads by content, not filename (#1381) (abc9601)
  • backend: validate event id before using it in the logo storage filename (#1382) (38b0e1d)
  • backend: validate the S3 endpoint host before the restore download (#1383) (ec03089)
  • gallery: bound and reclaim storage reads in the remaining zip builders (#1410) (70f5a8c)
  • gallery: keep an admin draft preview out of the guest share-login flow (f92d4bb)
  • gallery: keep videos playable under enhanced and maximum protection (#1404) (1080388)
  • gallery: let an admin preview a draft through its short share URL (f92d4bb)
  • gallery: let an admin preview a draft through its short share URL (#1405) (f92d4bb)
  • upload: let the csrf gate pass application/octet-stream chunks (#1401) (7c0c5c1)
  • upload: stop buffering a chunk body before anything checks its size (#1406) (4622478)

Don't miss a new picpeak release

NewReleases is sending notifications on new releases.