Changelog

3.1.6 2026-10-07

Changed

3.1.5 2026-10-05

Fixed

  • Fixed a moderate-severity resource consumption vulnerability.
  • Fixed a low-severity information disclosure vulnerability.

3.1.4 2026-10-02

Added

  • Added optional signed-in user binding for generated download tokens.
  • Added configurable file-count and uncompressed-size limits for generated archives.

Changed

  • Reduced memory usage by streaming assets through disk-backed temporary files while building archives.

Fixed

  • Fixed duplicate asset filenames overwriting earlier files in generated archives.
  • Fixed invalid archive-name values being coerced into unintended filenames.
  • Fixed a low-severity information disclosure vulnerability affecting concurrent archive downloads.
  • Fixed a moderate-severity information disclosure vulnerability.

3.1.3 2026-09-30

Changed

  • Route plugin settings through the plugin’s authorized settings controller.

3.1.2 2026-09-14

Changed

  • Align documentation filenames with page titles and update internal links.
  • Updated documentation for clearer, more consistent guidance.

3.1.1 2026-09-13

Changed

  • Normalize plugin settings.

3.1.0 2026-08-14

{warning} Anonymous downloads that pass raw asset IDs (files[]) will stop working until you mint a signed token in Twig. Update frontend templates before upgrading — see Upgrading to signed downloads.

Added

  • Added access control for downloads: anonymous requests require a signed token; raw asset IDs are only allowed for logged-in users who can view each asset.
  • Added allowedVolumes and defaultTokenDuration settings (CP and config/squeeze.php).
  • Added signed download tokens via craft.squeeze.createToken() and craft.squeeze.getDownloadUrl() (accept asset IDs or Asset elements).

Changed

  • Archive filenames are now sanitized before use.
  • Security: the legacy anonymous files[]=<id> download URL no longer authorizes downloads on its own.

3.0.0 2024-10-25

Changed

  • Now requires Craft 5.0+.