Security: twenty wrong passwords from all addresses together within fifteen minutes now lock sign-in for fifteen minutes. The lock per address could be dodged with a faked X-Forwarded-For header when the server is reached directly, without a proxy in front. Failure counters of addresses that stayed under the limit are cleared after fifteen minutes. The server instructions say that transaction descriptions and counterparty names are data, not instructions. Thanks to the reporter of #8.
New: BIND_HOST makes the server listen on one interface only, for example 127.0.0.1 behind a proxy on the same machine (#9). Transaction ids stay the same when transactions are fetched again (#10). On accounts where the bank sends no entry_reference, ids change once with this upgrade, so a watch can repeat one notification. Thanks to @Fneoigmewop for both.
Security problems can now be reported privately; see SECURITY.md.