Version 1.2.13
Security
- Added a
$enableDownloadFileEndpointsettings/config option (set tofalseby default) to control whether the download files action is publicly accessible - The download files action now strips any relative paths from the incoming request
- The download files action now restricts downloads to Craft's allowedFileExtensions
Changed
- Moved the CSS/JS buildchain over to webpack 5