← All updates
Changed

Security pass on the API and the extension

Four things closed after an audit of the API, the skill and the team extension. The extension signs every post it sends with a secret you paste once in its options page (version 1.31.0), and the server can now refuse anything unsigned. The server no longer fetches a media URL that points at a private or local address, whoever sends it. An uploaded file is refused when its bytes do not match its extension. And a token can be created for an owner or an admin only by the owner, because a token carries every right of the person it belongs to.

Try it in the app β†’