⚠️ Important security update that fixes vulnerabilities related to XSS and API key management
As of Octoprint 1.10.0, you are required to re-enter your password on critical operations (e.g. adding/changing/deleting users and groups, installing plugins, revealing the deprecated global API key, etc).
🔒 Security fixes:
- Fixed vulnerabilities in the login dialog and application key confirmation dialog
- Fixed vulnerability related to API key management that could allow unauthorized access
- Improved security of internal key generation
- Removed version number from discovery to prevent information leakage
🐛 Bug fixes
- Fixed a translation string in the German translation.
- Fixed a third-party dependency change that broke a development command.
- Improved the behavior of the "Hide successful prints" filter in the file list.
🐛 Bug fixes:
- Fixed issues with reverse proxy configuration
- Fixed file list caching behavior
- Fixed plugin installation queuing
Full release notes are found at https://github.com/OctoPrint/OctoPrint/releases