Added
- Add Salesforce Client Credentials authentication with configurable My Domain support. (#2961)
- Add the
allowLegacySignatureImageUrlsconfig setting to disable unsigned Signature image URLs for existing submissions.
Changed
- Protect Signature image URLs for new submissions with field-scoped access tokens while preserving URLs in previously sent email notifications.
Fixed
- Fixed a moderate-severity authorization vulnerability. (GHSA-q6g7-g2wg-h43h)
- Fix field variables in notification email address settings resolving to rendered HTML when custom email templates are used. (#2974)
- Fix OAuth integrations failing to connect after authorisation. (#2973)
- Fixed OAuth callback transaction validation.
- Fixed authorization for connecting and disconnecting OAuth integrations.
- Fixed a moderate-severity information disclosure vulnerability. (GHSA-rh4q-6j5r-8jqf)
- Fixed a moderate-severity authorization vulnerability. (GHSA-p696-447f-9258)
- Fixed a moderate-severity authorization vulnerability. (GHSA-qg3f-hm4x-h5h8)
- Fixed a moderate-severity information disclosure vulnerability. (GHSA-963f-vfpf-f85p)
- Fix slow GraphQL schema creation and form rendering when integrations have large cached settings. (#2972)
- Fix email notifications failing when their content references an empty optional field.
- Fix email notifications failing when their content references a deleted field.
- Fix PHP 8.4 deprecation warnings caused by implicitly nullable parameters and CSV parsing. (#2970)