Security

Security updates for request handling and admin mail settings

We closed a known weakness in how zerolog.ch reads incoming requests, narrowed who can open the admin alert mail settings and tightened the waitlist pages. You do not need to do anything.

A weekly check of the server's third-party libraries flagged a weakness in the part that reads form and query data sent to zerolog.ch. The update that fixes it could not ship last week because two of our own checks failed. Those checks were reading an outdated layout of the site files, not finding a real fault.

We fixed the checks, confirmed that sign-in and password changes behave the same before and after the update, and shipped it today. The dependency scan of the live server now reports no known weaknesses.

A second change today concerns the admin area. The settings for our internal alert mail, including the sign-in details of the mailbox that sends those alerts, could be opened by every administrator. They now follow the same rule as the other mail settings: only administrators who may change settings can view or edit them. Customer accounts never had access to these settings.

The waitlist pages for confirming or leaving the list carry a personal code in their address. They are supposed to tell your browser not to pass that address on when you follow a link. A site-wide default replaced that instruction with a looser one. Both pages send the strict setting again, and the page itself now repeats it, so a later change to the site-wide default cannot undo it.

Your account, chats and settings are unchanged. There is nothing to reinstall or reset.

Corrections are entries here too. If something on this page is wrong, say so. Feed · Docs · Legal & privacy · Home