Skip to content

Security fixes: #851, #870, #873#874

Open
edgeinfinity1 wants to merge 3 commits intoJrohy:masterfrom
edgeinfinity1:main
Open

Security fixes: #851, #870, #873#874
edgeinfinity1 wants to merge 3 commits intoJrohy:masterfrom
edgeinfinity1:main

Conversation

@edgeinfinity1
Copy link
Copy Markdown

@edgeinfinity1 edgeinfinity1 commented Dec 10, 2025

This PR includes #863 to fix #851. I rewrote some authentication code to fix #870 and #873.

Please note that I only made minimal tweaks to block the vulnerability, which is likely NOT the best solution for the entire project.

I have tested on my own deployment and it works, but I'm not sure if there are potential issues. I suppose this can be merged as a temporary solution.

@edgeinfinity1
Copy link
Copy Markdown
Author

BTW: This project caches seemingly every GET request with NGINX, make sure you reboot your server to fully apply any changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security vulnerability 管理员密码无故失效

2 participants