v1.7.1 #1460
nielsdrost7
started this conversation in
General
v1.7.1
#1460
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
v1.7.1
InvoicePlane v1.7.1
Many thanks to @IamLeandrooooo, @SonNTB21DCAT164, and @lukasz-rybak for their contributions.
Security Improvements
This release addresses several potential XSS (Cross-Site Scripting) concerns by properly sanitizing and escaping key fields across the application. These changes improve security without affecting user workflow.
Fields now properly sanitized and escaped:
Additional improvements:
Bug Fixes and Improvements
Important Security Notice: SVG Logo Files
SVG logo uploads have been disabled due to security risks. SVG files can contain embedded scripts that could be exploited for XSS attacks. Only safe image formats are supported:
Impact on existing SVG logos:
Conversion options:
Online converters:
Desktop software:
Inkscape conversion steps:
Full Changelog: v1.7.0 → v1.7.1
This discussion was created from the release v1.7.1.
Beta Was this translation helpful? Give feedback.
All reactions