- Official Post
Hi,
there is another update:
Post
RE: krpano 1.22 - Reactive APIs, ThreeJS 3D Plugin, krpano Maps, Improved Javascript APIs, Custom Encryptions
Hi,
versions 1.22.4 and 1.20.12 have been updated again: now build 2025-03-06.
The passQueryParameters setting has been improved. The values of allowed parameters are more restricted now and now not even theoretical possible injecting cases should be possible anymore, especially in version 1.20.12, which was less secure compared to 1.22.4 before.
Btw - if using Panotour Pro built tours with deep-linking, there the passQueryParameters can be changed to:
(Code, 1 line)
to keep the deep-linking working…
versions 1.22.4 and 1.20.12 have been updated again: now build 2025-03-06.
The passQueryParameters setting has been improved. The values of allowed parameters are more restricted now and now not even theoretical possible injecting cases should be possible anymore, especially in version 1.20.12, which was less secure compared to 1.22.4 before.
Btw - if using Panotour Pro built tours with deep-linking, there the passQueryParameters can be changed to:
(Code, 1 line)
to keep the deep-linking working…
klaus.krpano
Now the passQueryParameter="..." setting should be absolutely secure in any case, all parameters are now filtered very strictly.
Best regards,
Klaus