Skip to content

v2.9.0 Features & Fixes - #924

Merged
jaredhendrickson13 merged 22 commits into
masterfrom
next_minor
Jul 29, 2026
Merged

v2.9.0 Features & Fixes#924
jaredhendrickson13 merged 22 commits into
masterfrom
next_minor

Conversation

@jaredhendrickson13

Copy link
Copy Markdown
Member

New

Breaking changes

  • RESTAPISettings hasync_username now must hold page-all privileges to successfully sync on HA peers
  • RESTAPISettings hasync must now be enabled on remote HA peers before settings sync can occur

Fixes

  • Addresses a potential privilege escalation issue in /api/v2/system/restapi/settings/sync
  • Fixes a weak deserialization pattern in /api/v2/system/restapi/settings/sync

TechAsen and others added 22 commits June 5, 2026 18:18
Co-authored-by: asenchooo <asenchooo@localhost.localdomain>
…i into next_minor

# Conflicts:
#	pfSense-pkg-RESTAPI/files/usr/local/pkg/RESTAPI/Models/FirewallRule.inc
@jaredhendrickson13 jaredhendrickson13 changed the title Next minor v2.9.0 Features & Fixes Jul 29, 2026
@jaredhendrickson13
jaredhendrickson13 merged commit d040fa6 into master Jul 29, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add HA Sync (XMLRPC config sync) endpoint (/api/v2/system/hasync) [Feature] Wireguard Peer Status

2 participants