Wappler 7.3.9 Released
Check the new Wappler site at https://wappler.io/
and download Wappler 7.3.9 from your Account Dashboard
Or just do “check for updates” on the Wappler tray icon for automatic install!
What's New
Security is always a top priority for us at Wappler, so in this week's update we have added new security middleware Helmet for specifying Secure headers in NodeJS Server Connect projects.
Now you can make your Server Connect NodeJS projects even more secure by specifying various security headers like Content Security Policy (CSP), X-Frame-Options, X-Content-Type-Options, Referrer-Policy and many more.
See HTTP Security Headers Configuration in Wappler for more details.
Wappler NodeJS 2.6.0
- New security middleware Helmet for specifying Secure headers
Server Connect
- Added Global Options for Content Security Policy (CSP)
- Fully integrate new Helmet options for specifying Secure headers
- Improve CSP options styling
Server Connect Settings
- Improved the Helmet options
- Auto add Helmet module if options are used
Local Node Server
- When running npm install to add node modules, stop the running server first, then start it when done
Content Security Policy Meta tags
- Added new content security policy meta tags with Wappler tuned default values for best page security
- improved content security policy meta tag help texts
Workflow Panel
- when visible on Wappler open, do not auto open the selected action but keep the last editor open
General
- Open external links on UI always in the browser
Project Assets Updater
- When updating Server Connect nodeJS files, skip package.json, .dockerignore and .npmrc if exists
- When updating Server Connect PHP files using composer, skip composer.json if it exists
AI Assistant
- Improve working of Claude models
Fixed issues
- Deepseek problem
- Claude (all versions) keep issuing a 500 error
- [AI] Internal Server Error
- Node configuration issues
- Safety Concerns using CDN for Bootstrap and Font Awesome 5 in Wappler
- Wappler sanitation to prevent XSS
- Http Security Headers in Wappler (nodejs)
- DmxRouting.js breaks CSP rules when <script> tags contain CSP Nonce
- Musings on Mobile App Development in Wappler with CORS
- Mobile app CORS trouble
- Better practice for modern CSP-compliant style
- No access to external resources (mobile app)
- CORS Policy help
- App Mobile and API connection
- Font Awesome blocked by Content-Security-Policy on mobile hybrid app
- Server connect on Android