← Changelog

Security hardening

v0.3.4
  • Removed the waitlist "secret key" from the Credentials tab — it was never used to authenticate anything, so it's gone rather than left sitting around
  • Added standard security headers (HSTS, no-sniff, referrer policy, and a frame-ancestors policy that blocks the app from being embedded elsewhere) to every response