September 30, 2026, 19:25

H-Script 1.0.7: security improvements

This release strengthens user content handling, CSRF protection, and access checks. Changing a password in the Configurator now requires the current password and confirmation of the new one. A stricter browser security policy is in place in report-only mode while we check compatibility.

Version 1.0.7 strengthens the handling of displayed content, forms, and account operations. It improves the processing of editor content, links, emails, and payment gateway data. User and administrator actions now have additional request authenticity and access checks. Changing the Configurator password requires the current password and confirmation of the new one.

A new browser security policy uses a unique nonce for each response. It currently collects reports in observation mode; enforcement will follow with future CMS updates. This update does not change the database schema.