Changes 06/03/2026 (v3.14.0)
release(v3.14.0): request validation hardening and symfony/yaml dependency update
Commit message
release(v3.14.0): request validation hardening and symfony/yaml dependency update
- security(csrf): enforce request-token checks on additional file and admin POST actions
- deps(composer): upgrade symfony/yaml to 8.0.12
Fixed
- Request validation hardening
- Added server-side CSRF enforcement to file creation and file share-link creation.
- Added CSRF enforcement to admin OIDC discovery and ClamAV self-test POST actions.
- Existing web UI flows continue to send the required CSRF token for these actions.
Changed
- Dependency security maintenance
- Updated
symfony/yamlto8.0.12in Composer dev dependencies and the locked dependency set.
- Updated
v3.14.0
Full Changelog
SHA-256 (zip)
bd68703dc9140caa8f7cbc8c1a4be004ef9e665d01316fd527fe38b0a76b99e5 FileRise-v3.14.0.zip