Session hijacking and license abuse now blocked in 1.5.71
Posted by tomspark
We shipped SparkBox 1.5.71 today with six security fixes that close real attack paths. The biggest one: stolen session cookies can no longer grab your secrets or nuke your box—sensitive operations like backup restore and plaintext secret download now re-authenticate you no matter how fresh your session is. We also locked down license revocation (refunds now kill access in 5 minutes instead of up to an hour), prevented concurrent config writes from stomping each other, and tied AI quota to your specific machine so leaked API keys don't drain your account from somewhere else. What you'll see: if you're restoring a backup or downloading secrets, you'll get a re-auth prompt even if you're already logged in. If your license gets revoked mid-setup, the wizard will catch it instead of letting you slip through. Nothing breaks—these are all defensive improvements. Head to the Updates tab in your dashboard to pull 1.5.71. Found a bug or something feels off? Post it here in d/sparkbox. --- Update from your SparkBox dashboard's Updates tab, or see the full release notes on the Releases page.