You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 72ea09f
Browse filesBrowse the repository at this point in the historyBrowse files
Berik Ashimov
authored and
Berik Ashimov
committed
Security hardening (v0.3.0)
- Breaking: admin panel is fail-closed; requests denied with 401 when no auth callable is configured (CWE-306)
- Detail view renders detail_fields() so hidden columns no longer leak (CWE-200)
- Extended sensitive/authorization field detection; matched fields forced read-only to prevent mass-assignment (CWE-915)
- CSRF cookie sets HttpOnly and Max-Age (CWE-1004)
- Security headers + CSP on admin HTML responses (CWE-1021)
- Non-integer page no longer 500s; page clamped (CWE-20)
- Security events logged (CWE-778)
Copy file name to clipboardExpand all lines: CHANGELOG.md
+12Lines changed: 12 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,5 +1,17 @@
1
1
# Changelog
2
2
3
+
## 0.3.0 — 2026-06-10
4
+
5
+
Security hardening — **breaking**.
6
+
7
+
-**Breaking:** the admin panel is now fail-closed — when no `auth` callable is configured, all requests are denied with HTTP 401 (previously they were silently allowed) (CWE-306). Pass an `auth` callable to enable access.
8
+
- Detail views render only `detail_fields()` (derived from `list_display` when configured), so columns hidden from the list no longer leak on the detail page (CWE-200).
9
+
- Sensitive/authorization field detection extended to `role`/`admin`/`superuser`/`permission`/`privilege`/`staff`/`scope`; matched fields are forced read-only unless explicitly opted into `form_fields`, preventing mass-assignment privilege escalation (CWE-915).
10
+
- CSRF cookie now sets `HttpOnly` and `Max-Age` (CWE-1004).
11
+
- Admin HTML responses carry `X-Frame-Options`, `X-Content-Type-Options`, `Referrer-Policy`, and a restrictive `Content-Security-Policy` (CWE-1021).
12
+
- Non-integer `?page=` values no longer cause a 500; page is clamped to a maximum (CWE-20).
13
+
- Security events (auth/CSRF failures, blocked mutations) are now logged (CWE-778).
0 commit comments