> This page is for Applications Protection.

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.humansecurity.com/llms.txt.

# Changelog

## September 30, 2025

## Version 7.3.6

### Added

* Support for `additional_risk_info` feature
* `is_sensitive_route` field to Risk API and async activities

## June 30, 2025

## Version 7.3.5

### Added

* Whitelist by request host name

## December 26, 2024

## Version 7.3.4

### Changed

* Automatically inspect GraphQL POST data

### Fixed

* GraphQL default path

## July 19, 2024

## Version 7.3.3

### Fixed

* Rate limit code for JSON responses

## July 17, 2024

## Version 7.3.2

### Fixed

* Rate limit code

## Version 7.3.1

### Changed

* Remove `lua-resty-nettle` version restriction

### Fixed

* Install PX package symlink in OpenResty Lua directory

## June 13, 2023

## Version 7.3.0

### Added

* CORS support
* Set `X-PX-COOKIES` as the default custom cookie name
* `_M.px_login_creds_settings` configuration, to allow specify CI settings in Lua configuration file

### Changed

* Rename `px_graphql_paths` to `px_graphql_routes`

### Fixed

* Correctly add GraphQL routes (requests must contain specified GraphQL Type/Name) to sensitive routes

## April 20, 2023

## Version 7.2.1

### Added

* `custom_sensitive_routes` a custom function to determine if URL path is a sensitive route

## April 13, 2023

## Version 7.2.0

### Added

* `custom_enabled_routes` a custom function to determine if url path is an enabled route
* `px_graphql_paths` to specify a list of GraphQL endpoints
* Support for JWT and `pxcts`

### Changed

* Support for multiple GraphQL endpoints

### Fixed

* Add CI paths to the sensitive routes

## June 27, 2022

## Version 7.1.3

### Fixed

* Export `ngx.ctx.pxde` variable

## June 22, 2022

## Version 7.1.2

### Fixed

* Properly handle multiple instances of the same header
* Field name in telemetry command

## May 10, 2022

## Version 7.1.1

### Fixed

* Call `enrich_custom_parameters()` only once

## April 20, 2022

## Version 7.1.0

### Added

* Credential Intelligence v2 protocol

### Changed

* Credential Intelligence v2 is the default protocol
* New block page

### Fixed

* Send `custom_params` with `page_req` and `block` activities

## March 21, 2022

## Version 7.0.1

### Added

* HypeSale support

## March 17, 2022

## Version 7.0.0

### Added

* GraphQL support
* `sensitive_routes` configuration

### Fixed

* Credential Intelligence code improvements and enhancement

## July 25, 2021

## Version 6.8.0

### Added

* Whitelist URI pattern support
* Page requested activity includes HTTP status code

## May 2, 2021

## Version 6.7.3

### Fixed

* Issue with request body in login credentials extraction

## March 20, 2021

## Version 6.7.2

### Added

* Support for form-urlencoded content type in login credentials extraction.

## March 19, 2021

## Version 6.7.1

### Added

* Support for multipart/form-data content type in login credentials extraction.

## March 17, 2021

## Version 6.7.0

### Added

* New feature: Login Credentials Extraction.

## October 16, 2020

## Version 6.6.2

### Fixed

* Handle cookies as table in `extract_cookie_names`.

_Showing the 20 most recent of 70 entries. Append `/llms.txt` to the changelog URL for the complete index._