diff --git a/.github/SECURITY.md b/.github/SECURITY.md index bb1c4446..9b9bcce1 100644 --- a/.github/SECURITY.md +++ b/.github/SECURITY.md @@ -59,7 +59,7 @@ For the cases where transactions are really needed, users can utilize the [Batch
List/Search side-channel attacks -Over the years we've implemented several extra checks to minimize the risk of List/Search side-channel attacks (see especially [v0.32.0](https://github.com/pocketbase/pocketbase/blob/master/CHANGELOG.md#v0320)) but users need to be aware that all client-side filtered fields are technically subject to timing attacks _(whether they are practical or not is a different topic)_. +Over the years we've implemented several extra checks to minimize the risk of List/Search side-channel attacks (see especially [v0.32.0](https://github.com/pocketbase/pocketbase/blob/master/CHANGELOG_23_39.md#v0320)) but users need to be aware that all client-side filtered fields are technically subject to timing attacks _(whether they are practical or not is a different topic)_. This is by design and it is accepted tradeoff between performance, security and usability. diff --git a/CHANGELOG.md b/CHANGELOG.md index a32457c7..3ef400cb 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,7 @@ - Included the recovered panic stack trace of `routine.SafeWrap` in the returned error (max 2KB). - Wrap the individual `up`/`down` JSVM migration arguments in `routine.SafeWrap` so that in case of panic we can still print the failed js migration filename. -- Updated `modernc.org/sqlite` to 1.59.0 _(minor performance improvement by switching to Go's `memmove`)_. +- Updated `modernc.org/sqlite` to 1.59.0 _(minor performance improvement by switching to Go's `memmove` on Linux targets)_. - Other minor fixes (godoc typos, normalized negative jsvm pool size, etc.).