This changelog summarizes hardening work in general terms. It deliberately omits exact locations, code, and attack paths.
Before: Administrative/branding actions could be reached with a shared credential alone. After: Those actions now require a signed-in site owner. A limited break-glass path remains for emergencies and is audit-logged.
Before: Some user-provided content could be rendered without full escaping in edge cases. After: Output escaping was tightened so user content is consistently neutralized.
Before: User-supplied links were stored and rendered as-is. After: Links are sanitized so unsafe URL schemes cannot execute.
Before: A sensitive credential was compared in a way that could leak timing information. After: Sensitive comparisons use a constant-time approach, and secrets are documented as environment values only.
Before: Uploads were validated primarily by file extension. After: Uploads are additionally checked so their real contents match the claimed image type.
Before: The response header policy left room for tightening. After: The Content Security Policy was extended and an explicit permissions policy was added.
Before: Some error responses could echo internal details. After: Client responses are generic; details stay in server-side logs.
Before: Client-side rules were inconsistent with server rules in places. After: Server-side rules are authoritative and consistently enforced.