From a585b935d5632f0a45eddfbb7762371c5122242f Mon Sep 17 00:00:00 2001 From: Alexandre Alapetite Date: Mon, 7 Apr 2025 10:15:03 +0200 Subject: Changelog --- CHANGELOG.md | 31 ++++++++++++++++++++++++++++++- 1 file changed, 30 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 7bb1285cb..e33ee836b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,17 +2,46 @@ See also [the FreshRSS releases](https://github.com/FreshRSS/FreshRSS/releases). -## 2025-0X-XX FreshRSS 1.26.2-dev +## 2025-04-XX FreshRSS 1.26.2-dev * Features * Implement JSON string concatenation with & operator [#7414](https://github.com/FreshRSS/FreshRSS/pull/7414) + * Support multiple JSON fragments in HTML+XPath+JSON mode [#7369](https://github.com/FreshRSS/FreshRSS/pull/7369) +* Bug fixing + * Fix escaping of tag search [#7468](https://github.com/FreshRSS/FreshRSS/pull/7468) + * Fix CLI parsing of Boolean flags [#7430](https://github.com/FreshRSS/FreshRSS/pull/7430) + * Fix API for labels with slash [#7437](https://github.com/FreshRSS/FreshRSS/pull/7437) +* Security + * Add `Content-Security-Policy` HTTP headers to favicons [#7471](https://github.com/FreshRSS/FreshRSS/pull/7471) + * Fix for extensions: Restrict valid paths in `ext.php` [#7479](https://github.com/FreshRSS/FreshRSS/pull/7479) + * Fix for extensions: Secure serving of user files [#7495](https://github.com/FreshRSS/FreshRSS/pull/7495) + * Use HTTP POST for logout [#7489](https://github.com/FreshRSS/FreshRSS/pull/7489) + * Disallow `