1.31.4 — Trusted token links and safe short-link previews
Editorial identity incomplete
2026-10-01
Token links now stay on configured frontends, and short-link preview pages escape the destination and preview text they render.
Security
- Token links (magic login, password reset, invite) now go only to a configured frontend. A
webapp_base_urlrequest value, a?group=outside the account's own tenant, and anOriginheader can select a configured frontend but cannot add one. - Short-link preview pages now escape the destination and the preview text.
Upgrade notes
- Set
WEBAPP_BASE_URL, andWEBAPP_ALLOWED_ORIGINSfor extra frontends.