Changelog
What the site has gained
Every change, newest first, as it was written down while the site was being built.
Atom feed of the changes4 changes
September 20264 changes
- Security
Plain-HTTP and
www.requests are redirected permanently tohttps://nathanz.cloud, so the sign-in form is never served in the clear. - Security
Every response carries security headers (no framing, nosniff, a referrer policy, a permissions policy, HSTS);
X-Powered-Byis no longer sent. - Security
A
?next=path containing a tab or newline could send a fresh sign-in to another site; return paths are now resolved as a browser would and kept only if they stay on the site. - Security
The origin check on scheduler writes, and admin invite links, no longer trust a client-sent
X-Forwarded-Host.