chiappa
|
5d3f05045f
docs: mark SEC_REVIEW F69 as fixed in de84fd9
|
3 дней назад |
chiappa
|
de84fd9b1d
fix: cap request body size before BodyParsingMiddleware reads it (SEC_REVIEW F69)
|
3 дней назад |
chiappa
|
df37f60943
docs: mark SEC_REVIEW F68 as fixed in df1a298
|
3 дней назад |
chiappa
|
df1a298c82
fix: gate /api/docs and openapi.yaml behind API_DOCS_PUBLIC (SEC_REVIEW F68)
|
3 дней назад |
chiappa
|
0345b90174
docs: mark SEC_REVIEW F66 and F67 as fixed in 4a764f5
|
3 дней назад |
chiappa
|
4a764f58f0
fix: remove unused APP_SECRET / UI_SECRET (SEC_REVIEW F66 + F67)
|
3 дней назад |
chiappa
|
5c2ecf7fd6
docs: mark SEC_REVIEW F65 as fixed in c439ce1
|
3 дней назад |
chiappa
|
c439ce1db3
fix: scrub raw JWTs and short Bearers in log output (SEC_REVIEW F65)
|
3 дней назад |
chiappa
|
a37e769d2c
docs: mark SEC_REVIEW F64 as fixed by F22
|
3 дней назад |
chiappa
|
637a7b92eb
docs: mark SEC_REVIEW F63 as fixed in d225bfe
|
3 дней назад |
chiappa
|
d225bfe6b9
fix: pin Twig autoescape strategy to 'html' (SEC_REVIEW F63)
|
3 дней назад |
chiappa
|
25f10f0d01
docs: mark SEC_REVIEW F62 as fixed in f044dbb
|
3 дней назад |
chiappa
|
f044dbb6bc
fix: drop style-src 'unsafe-inline' (SEC_REVIEW F62)
|
3 дней назад |
chiappa
|
75e6df3060
docs: mark SEC_REVIEW F61 as fixed in 3556cd1
|
3 дней назад |
chiappa
|
3556cd1920
fix: extend Permissions-Policy deny-list to full hardening (SEC_REVIEW F61)
|
3 дней назад |
chiappa
|
6ff3720983
docs: mark SEC_REVIEW F60 as fixed in 68121fe
|
3 дней назад |
chiappa
|
68121febe2
fix: make HSTS header operator-tuneable for preload opt-in (SEC_REVIEW F60)
|
3 дней назад |
chiappa
|
a1356f9eb2
docs: mark SEC_REVIEW F59 as fixed in 206db1e
|
3 дней назад |
chiappa
|
206db1e492
fix: add COOP / CORP / Cross-Domain-Policies headers (SEC_REVIEW F59)
|
3 дней назад |
chiappa
|
b2d81caa70
docs: mark SEC_REVIEW F58 as fixed in 95e206c
|
3 дней назад |
chiappa
|
95e206c436
fix: pin RapiDoc CDN load with SRI hash on /api/docs (SEC_REVIEW F58)
|
3 дней назад |
chiappa
|
6b06ff379e
docs: mark SEC_REVIEW F57 as fixed in 67011c8
|
3 дней назад |
chiappa
|
67011c8cea
fix: prefix session cookie with __Host- in production (SEC_REVIEW F57)
|
3 дней назад |
chiappa
|
de80c1f318
docs: mark SEC_REVIEW F56 as fixed by F24 (193f646)
|
3 дней назад |
chiappa
|
ee1582d904
docs: mark SEC_REVIEW F55 as fixed by F24 (193f646)
|
3 дней назад |
chiappa
|
ea92c3d093
docs: mark SEC_REVIEW F54 as fixed in 1ed16c0
|
3 дней назад |
chiappa
|
1ed16c03a3
fix: Origin/Referer + JSON-body checks on CsrfMiddleware (SEC_REVIEW F54)
|
3 дней назад |
chiappa
|
f54d83d21e
docs: mark SEC_REVIEW F53 as fixed by F24 (193f646)
|
3 дней назад |
chiappa
|
6f5429e958
docs: mark SEC_REVIEW F52 as fixed in e5b525b
|
3 дней назад |
chiappa
|
e5b525b393
fix: strip C0/C1 control chars from admin string fields (SEC_REVIEW F52)
|
3 дней назад |