This commit is contained in:
@@ -2,6 +2,15 @@
|
||||
|
||||
# Changelog
|
||||
|
||||
## v0.1.0-preview.15 — 2026-09-03
|
||||
|
||||
- Permit applications to opt into an exact non-default HTTPS WebAuthn origin
|
||||
port for `localhost` and reserved `.test` relying-party IDs. The configured
|
||||
origin remains exact, production origins remain portless by default, and
|
||||
malformed, default, non-canonical, zero, or out-of-range ports fail closed.
|
||||
- Record the Gamertan local-Caddy dogfood pressure that required this explicit
|
||||
development boundary without weakening cross-origin ceremony rejection.
|
||||
|
||||
## v0.1.0-preview.14 — 2026-09-03
|
||||
|
||||
- Reject header-only, truncated, and structurally invalid PDF uploads in the
|
||||
|
||||
Reference in New Issue
Block a user