## bunkerity/bunkerweb — v1.6.16-rc2…v1.6.16-rc3

_76 commits._

### Features
- **feat(headers): deny publickey-credentials-remote-client-data-json by default** (4fe1c9c)
- **Merge pull request #3066 from rayshoo/add-samesite-none-on-cookie-flags** (fe151f2)
- **feat(letsencrypt): issue and serve certificates for public IPv4 addresses** (bd8d43d)
- **feat(redis): add redis cluster support** (5469882)
- **feat(lists): parse JSON, NDJSON, CSV and tab-separated IP list URLs** (f8f88cc)
- **feat: add SameSite=None support for Set-Cookie flags** (6ff1e7b)

### Fixes
- **fix(ui): start the all-in-one Web UI without Python's _zstd module** (2333734)
- **fix(headers): refuse COOKIE_FLAGS values the cookie flag module rejects** (e7f2702)
- **fix(headers): bound the cookie flag module's scans of Set-Cookie values** (60fb730)
- **fix(ui): pick up plugin pages updated a few seconds apart** (6a701d6)
- **fix(ui): translate the RAW editor draft help in every locale** (5297db3)
- **fix(scheduler): publish upstream TLS material changes from the grpc and reverseproxy jobs** (bf948e9)
- **fix(errors): serve custom error pages to blocked non-GET requests** (095aa84)
- **fix(autoconf): take the gateway backend scheme from KUBERNETES_SERVICE_PROTOCOL** (e1d344c)
- **fix(bunkerweb): keep access controls enforced on a restart that keeps its config** (5c8c205)
- **fix(db): read a template's SERVER_NAME from its default in single-site mode** (b47c950)
- **fix(db): serve every SERVER_NAME entry in single-site mode** (513ac59)
- **fix(headers): stop the cookie flag module reading and writing past its buffers** (eb98e47)
- **fix(letsencrypt): publish renewed certificates to the instances** (d7bf3b3)
- **[#3992] fix(misc): serve the default page on / only and 404 elsewhere** (a44b0c7)
- **[#3990] fix(ui): open the plugin's section of the Features page from "More info"** (2c5bef2)
- **[#3991] fix(ui): keep the loading page until every config save has finished** (971af9b)
- **fix(backup): pass --routines to mariadb-dump only for MariaDB** (6d9158b)
- **fix(ui): keep the settings of services whose name starts with a renamed one** (889901a)
- **fix(db): warn when two services share a server name** (a3c2d81)
- **fix(jobs): load only the running job's cache blobs and cap the bunkernet report queue** (61e732f)
- **fix: carry SameSite=None support as a deps patch** (8fe0680)
- **fix(healthcheck): keep /healthz ok while a configured instance reloads** (3970f14)
- **fix(ui): initialise the bans table tooltips** (4cf9e9d)
- **[#3965] fix(db): sweep chunk sets when job caches, services or plugins are deleted** (32deffb)
- **[#3965] fix(db): never sweep chunk sets saved during the sweep** (eda62df)
- **fix(ui): keep the active PRO menu entry readable in dark mode** (5ce99de)
- **perf(ui): measure the table once when restoring hidden columns** (5e1eb33)
- **perf(ui): use one delegated tooltip for the reports table** (66dd9f2)
- **fix(ui): add missing breadcrumb and modal translation keys** (cfcd304)
- **fix(ui): pick the session cookie per request for mixed proxied and direct access** (e114cc5)
- **fix(ui): stop asking to restart the web UI for plugins without a page** (3c3ce4d)
- **fix(ui): stop deleting services that share a server name on edit** (4312692)
- **[#3965] fix(db): store large blobs in chunks so no max_allowed_packet tuning is needed** (405be72)
- **fix(db): keep unchanged PRO plugin pages on force update** (d6bbd1b)
- **[#3986] fix(ui): stop rewriting other services when one is created or deleted** (6871603)
- **[#3969] fix(ui): keep DataTables toolbar groups whole when they wrap** (83462ec)
- **[#3963] fix(ui): hold page scripts until translations are loaded** (bd5af8b)
- **fix(ui): pick the session cookie name before Flask opens the session** (89e748c)
- **[#3988] fix(core): answer the loading page with 503 and Retry-After** (de45497)
- **fix(redis): validate cluster nodes and escape keys** (d945177)
- **fix(metrics): key Redis metrics per instance so instances sharing a Redis stop overwriting each other** (cc6fb00)
- **Merge pull request #3972 from MageInt/fix(metrics)-stop-resyncing-unchanged-metrics-to-Redis-every-timer-tick** (12a6e98)
- **fix(ui): accept form fields up to MAX_CONTENT_LENGTH for signed-in users** (80db013)
- **fix(ui): keep static folder urls free of the version query so country flags load** (2a730d9)
- **fix(metrics): leave a table unsynced when a full rewrite gets an unexpected length** (03155eb)
- **fix(metrics): check every synced key instead of a marker when no TTL is set** (e4f6ecf)
- **fix(metrics): detect lost Redis keys with a sync marker when no TTL is set** (5b1675a)
- **fix(metrics): stop resyncing unchanged metrics to Redis every timer tick** (fd500a6)

### Backend
- **Road to 1.6.16~rc3 🚀** (d415724)
- **Merge branch 'dev' of https://github.com/bunkerity/bunkerweb into dev** (0e1fe15)
- **deps: update ModSecurity to v3.0.17 and libmaxminddb to v1.14.1** (ba32978)
- **[#2137] docs(ha): document floating IP failover with keepalived** (2fa570b)
- **Prepare for 1.6.16~rc3 🚀** (46a2edc)
- **[#3966] docs(changelog): reference the IPv6 rDNS issue** (d78bb3c)

### Tests
- **test: pin https for the samesite_none headers scenario** (7d34cbd)
- **test: assert raw Set-Cookie SameSite attribute in headers tests** (be3a6db)
- **test: cover SameSite=None and value-less SameSite in headers tests** (d7208a7)
- **test: remove obsolete X-XSS-Protection checks from headers tests** (bc8f415)

### Docs
- **docs(changelog): date the 1.6.16~rc3 section** (c50bbc4)
- **docs(changelog): tidy the 1.6.16~rc3 section and order entries by category** (83203e8)
- **docs(changelog): credit rayshoo for SameSite=None cookie flags** (aa295ba)
- **docs: fix references, examples, links, and translations across all locales** (9e8fc54)
- **docs(concepts): raise MariaDB to v13 and MySQL to v26 in the compatibility matrix** (774907f)
- **docs: move SameSite=None guidance to headers plugin READMEs** (1e089f6)
- **docs(changelog): credit MageInt for the incremental metrics sync** (cb70f0a)

### Chore
- **build(docker): pin pcre2, nghttp2-libs, libpng and python3 3.14.8 to clear the Trivy gate** (5691026)
- **build(ui): merge the overrides.css imports at image build** (9e950ff)
- **refactor(ui): split overrides.css into topic parts behind an @import index** (a196f4e)
- **chore(docs): Small doc fixes** (11c0eac)
- **chore(docs): Move Building from source documentation to the Integrations page** (fd29306)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/bunkerity/bunkerweb?utm_source=github-action)._