Tags: dereuromark/cakephp-feedback
Tags
Use plugin-specific i18n domain for translations (#24) Convert __() calls in src/ and templates/ to __d('feedback', ...) so user-facing strings live in their own translation domain instead of leaking into the host app's default domain. The 41 pre-existing __d('feedback', ...) calls already pointed at the right domain — the rest of the plugin now matches. Also refresh resources/locales/feedback.pot via cake i18n extract. The POT was ~8 years stale (POT-Creation-Date 2018-01-16) and missed all the strings added in the admin backend since then. Switch to --no-location while regenerating so future regenerations stay tidy. Existing language files (de/, es/, nl/, sv/) are intentionally left alone — translators can run msgmerge against the refreshed POT to pull in the new msgids without losing existing translations.
Fix critical security vulnerabilities (#18) This commit addresses critical security issues: **CRITICAL:** - Fix unsafe deserialization (RCE vulnerability) in Filesystem store - Use unserialize() with allowed_classes => false to prevent object injection - Maintains backward compatibility with existing array-based serialized files - Fix path traversal vulnerabilities in file operations - Add strict file format validation with regex (alphanumeric session IDs) - Use realpath() to prevent directory traversal attacks - Validate files are within allowed directory - Add screenshot validation to prevent abuse - Validate base64 format with regex for data URIs - Enforce 3MB size limit on encoded data - Allow non-URI values for backwards compatibility All changes maintain backward compatibility while preventing RCE, path traversal, and DoS attacks. All tests pass (21/21), PHPCS and PHPStan checks pass. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude <noreply@anthropic.com>
PreviousNext