[ P1 ] RELEASE NOTES ·
Secure Browser 0.1.4
Withdrawn. Do not install
This version has been withdrawn. It is no longer offered on AWS Marketplace and
must not be installed. If a stack runs 0.1.4, upgrade it to 0.1.6.
Security hardening release.
- Licensing: the Marketplace licence check now also runs when each browser session starts its stream, with automatic retries if the metering service is briefly unavailable.
- Identity: users whose email address is not verified by the identity provider are refused (403). OIDC providers must send email_verified (see the OidcEmailVerifiedClaim parameter). The first administrator is bound to their user ID on first sign-in.
- Browser lockdown: JavaScript runs without JIT by default (admins can re-enable it per policy profile), more Chrome management policies are enforced, browser internal pages such as chrome://flags are blocked, and DNS-over-HTTPS is off.
- File transfer: closes a gap where a file could leave as a print when downloads were disabled; transferred files are recorded with a SHA-256 hash in the audit log; copying remote text to the local clipboard now needs a click.
- Deployment: the stack is limited to AWS Regions that support Marketplace metering; ImageUriOverride must be digest-pinned.
- Upgrade: update the stack with the 0.1.4 template URL and keep the current parameter values.