Security-hardening release — the storefront/editor half of the SECURITY-571 audit —
plus dependency updates. No functional or visual changes to the storefront; existing
sites are unaffected. Pairs with jahia-store 5.0.1.
🔒 Security (#29)
- Client-side magic-byte validation of icon/screenshot uploads (#28) — the editor
now reads the actual leading bytes of a picked file and confirms a real raster
signature before uploading, catching a renamed SVG/HTML in the browser. It uploads
the detected MIME type rather than the spoofable File.type. This pairs with the
authoritative server-side re-validation shipped in jahia-store 5.0.1. - Defense-in-depth publish gate in the detail view (#54) — an unpublished
module/package never renders its detail (description, FAQ, author, download URLs) to
a visitor without edit rights, even if the backend render filter is bypassed. Owners
keep the draft preview.