← All releases

v0.18.2

securityfix

Hardens Cloudflare password access across translated routes, protected assets, and Pages deployment configuration.

Password access hardening

  • Authorizes decoded request paths so encoded separators cannot bypass protected routes.
  • Protects translated collection URLs under every configured language prefix.
  • Prevents image processing from publishing derivatives of protected assets under public /static paths, clears stale local derivatives, and denies retained legacy private-asset URLs.
  • Generates a fail-closed Cloudflare _routes.json and rejects conflicting custom route configuration.
  • Stages password secrets for both production and preview deployments.
  • Clarifies that password changes take effect on the next deployment, when existing signed sessions are invalidated.