Skip to content

Latest commit

 

History

History
32 lines (24 loc) · 1.13 KB

File metadata and controls

32 lines (24 loc) · 1.13 KB

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[2.0.4] - 2026-05-08

Security

  • CRITICAL: Fixed JWT signature verification vulnerability (GHSA-223g-f5mq-gw33)
    • Enabled proper JWT signature verification in backend/routes/dashboard.py
    • Enabled proper JWT signature verification in backend/main.py
    • Enabled proper JWT signature verification in backend/activity_logger.py
    • Replaced verify_signature=False with cryptographic verification using JWT_SECRET_KEY
    • Prevents JWT forgery attacks and unauthorized account takeover
    • CVE: Pending

Changed

  • JWT tokens are now verified with the server's secret key
  • Forged tokens will be properly rejected with authentication errors

[2.0.3] - 2026-04-15

Added

  • Initial release with adaptive quizzes
  • AI-powered course recommendations
  • Code compilation and practice features
  • Dashboard analytics
  • MetaMask wallet integration
  • Certificate NFT generation