MailFlow v3.8.2
Two security fixes for signed-in sessions. Update when you can. Thanks to @Monkey7539 for both.
Security
- The screen lock did not cover SSO sign-in (#553). From a locked MailFlow tab, someone at the keyboard could start an SSO sign-in, and on installs with SSO set up this could get past the lock or link another identity to the locked account. A locked session now refuses SSO sign-in and linking until it is unlocked or signed out.
- New mail kept reaching a session after it ended (#554). A browser tab that was signed out, locked, or cut off by a password reset could keep receiving live updates, including new messages' senders, subjects and previews, until the connection dropped. Signing out, locking, and resetting a password now close those connections.
Upgrading
ghcr.io/maathimself/mailflow-backend:latest points at 3.8.2, published for amd64 and arm64. There are no database migrations. Tabs opened on 3.8.0 or later reload into the new version by themselves; reload any older ones.