This release includes 1 security fix for security teams reviewing exposed deployments.
Published 26d
Developer Productivity
✓ No known CVEs patched
This release patches 1 known CVE
Topics
form
form-builder
laravel
marketing-tools
nuxt
saas
Affected surfaces
auth
Summary
AI summaryUpdates Validation, Related, and PR across a mixed release.
Full changelog
This release fixes two self-hosted issues affecting PDF templates and password-protected forms.
Fixed
- Fixed PDF template zones being placed out of reach when adding fields to a tall PDF page. Newly added zones now stay visible and can be dragged normally.
- Fixed password-protected forms on plain-HTTP self-hosted instances. Firefox rejected the previous secure-only password cookie on non-HTTPS origins, which made valid passwords appear invalid. HTTPS deployments keep the secure cookie behavior.
Validation
- Reproduced the password issue in Firefox on a local HTTP self-host-style origin, then verified the form unlocks correctly after the fix.
- Verified newly added PDF zones stay visible and draggable in the PDF template editor.
- Ran frontend lint and targeted backend password form tests.
Related
- PR: https://github.com/OpnForm/OpnForm/pull/1184
Security Fixes
- Password cookie handling for self‑hosted plain‑HTTP instances no longer rejects valid passwords in Firefox due to secure‑only flag.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Earlier breaking changes
- v2.0.0 Requires running new database migrations before using V2 features.
Beta — feedback welcome: [email protected]