Breaking change: Movary now requires a new APPLICATION_SECRET environment variable. See .env.example for more details.
What's Changed
- Feature: Add table header sorting by @leepeuker in #840
- Feature: Paginate and filter job queue by @leepeuker in #841
- Feature: Paginate location settings by @leepeuker in #842
- Feature: Move password resets to dedicated page by @leepeuker in #844
- Feature: Paginate and filter user management by @leepeuker in #843
- Feature: Paginate password reset management by @leepeuker in #845
- Fix: Fix stale frontend assets and responses by @leepeuker in #858
- Maintenance: Replace native browser dialogs by @leepeuker in #846
- Maintenance: Reuse shared confirmation dialogs by @leepeuker in #848
- Maintenance: Reuse shared dialogs for remaining confirmations by @leepeuker in #849
- Maintenance: Inject application secret value by @leepeuker in #852
- Maintenance: Add sessionless password reset flash message by @leepeuker in #857
- Maintenance: Refactor flash message handling in controllers by @leepeuker in #861
- Maintenance: Remove PHP session dependency by @leepeuker in #860
- Security: Use unsafe methods for state-changing routes by @leepeuker in #850
- Security: Add stateless CSRF token primitives by @leepeuker in #851
- Security: Issue and propagate CSRF tokens by @leepeuker in #853
- Security: Enforce CSRF and API boundaries by @leepeuker in #854
- Security: Protect Plex authentication callback by @leepeuker in #855
Full Changelog: 0.76.0...0.77.0