Commit History

Autor SHA1 Mensaxe Data
  chiappa 2c3b65b469 fix: revalidate UI session against api periodically (SEC_REVIEW F36) hai 4 días
  chiappa 9b09048f24 docs: mark SEC_REVIEW F35 as fixed in d39ab01 hai 4 días
  chiappa d39ab01a7c fix: validate INTERNAL_JOB_TOKEN entropy at api boot (SEC_REVIEW F35) hai 4 días
  chiappa 1409ff2179 docs: mark SEC_REVIEW F34 as fixed in 3a4026b hai 4 días
  chiappa 3a4026baf6 fix: log fingerprints, not raw identifiers, in auth flows (SEC_REVIEW F34) hai 4 días
  chiappa 6a0aa27c61 docs: mark SEC_REVIEW F33 as fixed in c9f9a45 hai 4 días
  chiappa c9f9a45664 fix: accept nullable email on /auth/users/upsert-oidc (SEC_REVIEW F33) hai 4 días
  chiappa e3fa0cc65c docs: mark SEC_REVIEW F32 as fixed in 0594305 hai 4 días
  chiappa 05943057b8 fix: batch-load admin IPs list per-row lookups (SEC_REVIEW F32) hai 4 días
  chiappa c8ea0ede68 docs: mark SEC_REVIEW F31 as fixed in 3a2564d hai 4 días
  chiappa 3a2564d14b fix: cap audit-log filter length and pagination depth (SEC_REVIEW F31) hai 4 días
  chiappa 6d4687476b docs: mark SEC_REVIEW F30 as fixed in 2cc1924 hai 4 días
  chiappa 2cc1924a4e fix: bound IPs search `q` to anchored IP-shaped prefix (SEC_REVIEW F30) hai 4 días
  chiappa d2e1b3b29c docs: mark SEC_REVIEW F29 as fixed in a997d65 hai 4 días
  chiappa a997d65818 fix: rate-limit /api/v1/admin/* (SEC_REVIEW F29) hai 4 días
  chiappa 20c5cce580 docs: mark SEC_REVIEW F28 as fixed in e09964b hai 4 días
  chiappa e09964b4ad fix: bound RateLimiter bucket map with LRU eviction (SEC_REVIEW F28) hai 4 días
  chiappa 8e7a5f7b46 docs: mark SEC_REVIEW F27 as fixed in 060119a hai 4 días
  chiappa 060119af27 fix: rate-limit pre-auth and unauthenticated paths (SEC_REVIEW F27) hai 4 días
  chiappa 5072c54f87 docs: mark SEC_REVIEW F26 as fixed in ce77454 hai 4 días
  chiappa ce77454c93 fix: never leak exception messages from JsonErrorHandler (SEC_REVIEW F26) hai 4 días
  chiappa 5f05743c4b docs: mark SEC_REVIEW F25 as fixed in 33e9198 hai 4 días
  chiappa 33e9198800 fix: tighten /internal/* gate to loopback by default (SEC_REVIEW F25) hai 4 días
  chiappa 921e17a693 docs: mark SEC_REVIEW F24 as fixed in 193f646 hai 4 días
  chiappa 193f6463a4 fix: drop CSP unsafe-inline/unsafe-eval via nonces + Alpine CSP build (SEC_REVIEW F24) hai 4 días
  chiappa c67734d80c docs: mark SEC_REVIEW F23 as fixed in f66ceaf hai 4 días
  chiappa f66ceaf095 fix: tighten openid-connect-php constraint to ^1.0.2 (SEC_REVIEW F23) hai 4 días
  chiappa 5a26a19be6 docs: add update workflow to README and an admin manual hai 4 días
  chiappa 5232f10cd9 docs: mark SEC_REVIEW F22 as fixed in d9006eb hai 4 días
  chiappa d9006ebae7 fix: build scheduler sidecar from pinned image (SEC_REVIEW F22) hai 4 días