Changelog
3.1.6 2026-10-07
Changed
- Require Verbb Base 3.0.20 or later so shared control-panel layouts use the current asset bundle namespace. (verbb-base#3 (opens new window))
3.1.5 2026-10-05
Fixed
- Fixed a moderate-severity resource consumption vulnerability.
- Fixed a low-severity information disclosure vulnerability.
3.1.4 2026-10-02
Added
- Added optional signed-in user binding for generated download tokens.
- Added configurable file-count and uncompressed-size limits for generated archives.
Changed
- Reduced memory usage by streaming assets through disk-backed temporary files while building archives.
Fixed
- Fixed duplicate asset filenames overwriting earlier files in generated archives.
- Fixed invalid archive-name values being coerced into unintended filenames.
- Fixed a low-severity information disclosure vulnerability affecting concurrent archive downloads.
- Fixed a moderate-severity information disclosure vulnerability.
3.1.3 2026-09-30
Changed
- Route plugin settings through the plugin’s authorized settings controller.
3.1.2 2026-09-14
Changed
- Align documentation filenames with page titles and update internal links.
- Updated documentation for clearer, more consistent guidance.
3.1.1 2026-09-13
Changed
- Normalize plugin settings.
3.1.0 2026-08-14
{warning} Anonymous downloads that pass raw asset IDs (
files[]) will stop working until you mint a signed token in Twig. Update frontend templates before upgrading — see Upgrading to signed downloads.
Added
- Added access control for downloads: anonymous requests require a signed token; raw asset IDs are only allowed for logged-in users who can view each asset.
- Added
allowedVolumesanddefaultTokenDurationsettings (CP andconfig/squeeze.php). - Added signed download tokens via
craft.squeeze.createToken()andcraft.squeeze.getDownloadUrl()(accept asset IDs or Asset elements).
Changed
- Archive filenames are now sanitized before use.
- Security: the legacy anonymous
files[]=<id>download URL no longer authorizes downloads on its own.
3.0.0 2024-10-25
Changed
- Now requires Craft 5.0+.