Skip to content

Releases: riverside/http-headers

Version 1.19.1

02 Sep 17:52
Compare
Choose a tag to compare
  • Added “clientHints” directive to “Clear-Site-Data” header
  • Added “credentialless” directive to “Cross-Origin-Embedder-Policy” header

Version 1.19.0

23 Jul 08:09
Compare
Choose a tag to compare
  • Fixed: SSRF vulnerability by an Admin user
  • Fixed: XSS vulnerability by an Admin user

Version 1.18.11

13 Jun 14:09
Compare
Choose a tag to compare

Patch for RCE by Admin user

Version 1.18.4

30 Apr 09:00
Compare
Choose a tag to compare
  • Added "X-Robots-Tag" header
  • Added "interest-cohort", "layout-animations", "legacy-image-formats", "oversized-images", and "wake-lock" directive to "Permissions-Policy" header
  • Added "cross-origin" value to "Cross-Origin-Resource-Policy" header
  • Added "navigate-to" and "prefetch-src" directives to "Content-Security-Policy" header

Version 1.18.1

31 Oct 17:22
Compare
Choose a tag to compare
  • Added “allow-downloads” and “allow-top-navigation-by-user-activation” to “sandbox” directive, part of CSP

Version 1.17.0

26 Jul 09:32
Compare
Choose a tag to compare
  • Added "Cross-Origin-Embedder-Policy" header
  • Added "Cross-Origin-Opener-Policy" header

Version 1.16.1

23 Jul 19:29
Compare
Choose a tag to compare
  • Fix resource versioning

Version 1.16.0

23 Jul 18:47
Compare
Choose a tag to compare
  • Added the "NEL" header
  • Fixed the "Report-To" header

Various improvements

09 Jun 08:33
Compare
Choose a tag to compare
  • Support of Brotli compression
  • Support of "SameSite" directive to cookies
  • Import/export function bugfixed
  • Code refactoring

Remove direct calls to cURL

10 Jan 17:39
Compare
Choose a tag to compare
  • Direct calls to cURL was removed