Skip to content

Commit 6529a67

Browse files
author
Andrew Welch
committed
Version 1.2.13
1 parent 7544bb4 commit 6529a67

File tree

1 file changed

+6
-1
lines changed

1 file changed

+6
-1
lines changed

CHANGELOG.md

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,11 @@
11
# Transcoder Changelog
22

3-
## 1.2.13 - UNRELEASED
3+
## 1.2.13 - UNRELEASED [CRITICAL]
4+
### Security
5+
* Added a `$enableDownloadFileEndpoint` settings/config option (set to `false` by default) to control whether the download files action is publicly accessible
6+
* The download files action now strips any relative paths from the incoming request
7+
* The download files action now restricts downloads to Craft's [allowedFileExtensions](https://craftcms.com/docs/3.x/config/config-settings.html#allowedfileextensions)
8+
49
### Changed
510
* Moved the CSS/JS buildchain over to webpack 5
611

0 commit comments

Comments
 (0)