Critical Vulnerability Information Change Description Commit ID: 5782b35 Committer: unocelli Commit Time: 2 days ago Related Issue: #2174 Main Fixes Prevent multiple responses in heartbeat handler Block guest access to scheduler mutation operations File Change Overview 3 files changed 42 lines added, 7 lines deleted Key Code Changes 1. server/api/index.js - Limit API request size: 2. server/api/jwt-helper.js - Add guest permission validation logic: 3. server/api/scheduler/index.js - Add request body check during scheduler data validation: - Handle POST and DELETE requests: Summary This commit primarily focuses on security improvements, including refined guest permission checks and API request size limits, preventing unauthorized access and data mutation operations. When secure mode is enabled, special attention is given to guest identity verification to prevent unauthorized actions.