github ulsklyc/yuvomi v2.65.3

6 hours ago

Security

  • A household member can no longer take back a paid housekeeping visit through its payment
    task (GHSA-82jf-c39w-vh8c).
    Since v2.64.1 a paid visit can only be changed, deleted or paid
    again by an admin (GHSA-4p5w-5346-8598). That boundary covered the visit but not the payment
    task linked to it: reopening the task in Tasks marked the visit unpaid again, and from there a
    member could change its amount or delete it. Moving the payment task of a paid visit out of
    done now needs an admin as well, whether from the task form, the checkbox, a swipe or a bulk
    action. Ticking the task off stays open to members, as paying the visit does. A member who used
    to correct an accidental tick by unticking the payment task now gets "Permission denied" and has
    to ask an admin.

Don't miss a new yuvomi release

NewReleases is sending notifications on new releases.