Back to Changelog
Panel Backend
v1.0.477
Fixed a false-positive security report from self-hosted app installers on multi-IP servers.
Improvement
1- Customer domain and subdomain nginx vhosts now also answer on loopback (127.0.0.1), so on-server self-checks reach the correct site instead of a permissive default vhost. Existing sites are unaffected; this applies to newly created or regenerated vhosts.
Bug Fix
1- Self-hosted application installers that verify their own security over the loopback interface (for example, forum installers) no longer falsely report protected files as publicly exposed on multi-IP servers.