Rate-limit headers (X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset, Retry-After) are now exposed via Access-Control-Expose-Headers, so browser JavaScript can read them and back off properly on 429
POST /api/upload/local now accepts the array-style form field names files[] and files[0], files[1], ... (as generated by PHP, Rails, axios and similar) in addition to files. Any other field name is rejected with an unexpected-file-field error that lists the accepted names
Changes
Rate-limit (429) error responses now include "success": false, consistent with every other API error. Clients that checked for the absence of success on errors should check success === false instead
The hourly upload limit counts requests (each can carry up to 20 files), not individual files. The 429 error message now says so
Version 2.3.0 September 30, 2026
Expiry
Expired files are gone the moment they expire. GET /api/file/{fileId}, GET /api/file/{fileId}/security, GET /{fileId}/download, GET /{fileId}/preview and the file page return 404 as soon as a file expires (previews show the expired-image placeholder)
Bug Fixes
Fixed some Excel, Word, PowerPoint and ZIP files being rejected as a "potentially executable archive" even though they were safe
Fixed CSV and text files that begin with the letters "MZ" being rejected as Windows executables
Fixed large uploads (over 10 MB) applying stricter content checks to text, code and Office files than smaller uploads, which could cause false rejections and security warnings
Security
Blocked file types are now enforced consistently for large (chunked) uploads
Version 2.2.2 September 28, 2026
Bug Fixes
Fixed files ending up without an extension when a custom name was used for a URL upload — a custom name without an extension now keeps the source file's extension (e.g. "my song" becomes "my song.mp3")
Security
Blocked file types are now also rejected for URL uploads that use a custom name, based on the source file's real extension
Version 2.2.1 September 28, 2026
Bug Fixes
Fixed uploads from a URL failing when the file had a non-English filename (Cyrillic, Chinese, Arabic, etc.) — encoded names in the link are now decoded correctly
Fixed very long filenames with multi-byte characters failing to save — names are now trimmed by bytes instead of characters and keep their file extension
Version 2.2.0 July 20, 2026
Upload Limit Increase
Maximum files per upload request increased from 10 to 20
Documentation Correction
Clarified rate limit wording: the 200/hour limit applies to upload requests, not individual files — each request can contain up to 20 files
Updated API docs, OpenAPI spec, FAQ, and About page to reflect the corrected terminology
Version 2.1.0 December 28, 2025
Performance Improvements
Faster file downloads with optimized CDN caching
Image previews now cache intelligently based on file expiry
Reduced latency for frequently accessed files
Better global delivery performance
Image Preview Enhancements
Expired images now show informative placeholder instead of broken icon
Preview endpoint more reliable with better error handling
CORS headers added for cross-origin image embedding
API Response Headers
New X-Cache-Seconds header shows cache duration
New X-File-Expiry header shows when file will be deleted
Added X-Tempfile-Status for easier file status checking
Bug Fixes
Fixed image previews showing broken icon after file expiration
Fixed cache headers causing inconsistent download speeds and file expiryTime
Improved reliability of file deletion via API
Version 2.0.2 December 5, 2025
File Validation Improvements
Smart filename sanitization - special characters auto-fixed instead of rejected
Better Unicode support for Chinese/Arabic filenames
Filename length validation by bytes for accurate handling
Security Enhancements
Improved security scanning with fewer false positives
Text-based code files excluded from script pattern detection
More accurate threat detection for binary files and archives
Version 2.0.1 December 1, 2025
Rate Limit Improvements
Upload limit increased to 200 requests per hour (was 10 requests/hour)
Download limit increased to 5000 per 15 minutes (was 50)
Better rate limiting for power users and shared IPs
Version 2.0.0 October 18, 2025
File ID Format Overhaul
Shorter, secure file IDs using 11 Base58 characters
Enhanced privacy - no timestamp metadata in URLs
Cryptographically random IDs with 1 in 10^28 collision probability
Cleaner URLs (e.g., /kN8mP2xQvR7/)
Backward compatible with legacy file IDs
Migration Notice
Version 2.0.0 introduces shorter file IDs but remains fully backward compatible. No code changes required - both old and new formats work seamlessly.