Hey there,
The next minor release is in the works and this is the changelog (so far):
Chevereto v3.14.0 pre-release notes
Hope you like the update,
Rodolfo.
P.S. If you want to join the beta please let me know in the comments below. Please note before asking beta access: A beta release is not intended to run in production, it doesn't have the same support response and is not stable.
The next minor release is in the works and this is the changelog (so far):
Chevereto v3.14.0 pre-release notes
- Added support for WebP
- Added brute force protection for cookie based login attempts
- Added auth token at /update (CSRF)
- Added HTTP only and secure cookie flags
- Added restricted paths for Bulk content importer
- Improved login system (device based)
- Fixed XSS vulnerability in site settings
- Fixed XSS vulnerability in user profile
- Fixed XSS vulnerability in WhatsApp share button
- Fixed bug in anywhere uploader [11710]
- Updated dependencies (composer)
- Deprecated $_SESSION based login
- Deprecated use of HTTP_* headers for client IP resolution
- Removed public access for Bulk importer job results
Hope you like the update,
Rodolfo.
P.S. If you want to join the beta please let me know in the comments below. Please note before asking beta access: A beta release is not intended to run in production, it doesn't have the same support response and is not stable.