v1.2.45Web App
1 min read

Authentication and Security Hardening

Hardened Google account linking, session invalidation, 2FA changes, same-origin mutations, and baseline security headers.

#What's Changed

  • [Security] Restricted Google sign-in and account linking to explicit, verified account states.
  • [Security] Revoked active sessions after password resets and required confirmation before disabling 2-Step Verification.
  • [Security] Added same-origin mutation protection and baseline browser security headers.