v0.35.2
makeplane/planev0.35.2Aug 31, 2026by github-actions[bot]
AI Summary
Significantly enhances dashboard security by hardening origin validation against DNS rebinding and smuggling. Fixes issues with remote CDP WebSocket query strings.
Key Highlights
- Hardened dashboard origin validation and reverse-proxy access
- Defense against DNS rebinding, form/header smuggling, and cross-origin requests
- Strict HTTPS allowlisting and token authentication for reverse proxies
- Fixed root remote CDP WebSocket URLs with query strings
New Features
- Dashboard security hardening
- Token authentication for reverse proxies
Full Release Notes
### Security - Hardened **dashboard origin validation and reverse-proxy access** with same-origin provenance enforcement that defends against DNS rebinding, form/header smuggling, and cross-origin requests. Reverse-proxied origins now require exact HTTPS allowlisting and generated token authentication, while tokenless IPv4 and IPv6 loopback access remains supported. Dashboard options are validated strictly, and CLI and MCP lifecycle behavior is aligned (#1738) ### Bug Fixes - Fixed **root remote CDP WebSocket URLs with query strings** to insert the required slash before the query while preserving the encoded query (#1735) ### Contributors - @ctate - @Railly