chiappa
|
8ff409fff2
fix: tighten /ips/{ip} route pattern to IP charset (SEC_REVIEW F43)
|
před 3 dny |
chiappa
|
782faf23f3
docs: mark SEC_REVIEW F42 as fixed in cc77749
|
před 3 dny |
chiappa
|
cc77749fca
fix: enforce role allowlist on UI policy proxies (SEC_REVIEW F42)
|
před 3 dny |
chiappa
|
af42ca5fbc
docs: mark SEC_REVIEW F41 as fixed in 4ca69f3
|
před 3 dny |
chiappa
|
4ca69f30b6
fix: dedicated audit row when reporter/consumer audit_enabled flips (SEC_REVIEW F41)
|
před 3 dny |
chiappa
|
8ac4af659f
docs: mark SEC_REVIEW F40 as fixed in 30c0604
|
před 3 dny |
chiappa
|
30c0604e49
fix: rotate CSRF token on session-id regeneration (SEC_REVIEW F40)
|
před 3 dny |
chiappa
|
35645140e0
docs: mark SEC_REVIEW F39 as fixed in 0c79c1b
|
před 3 dny |
chiappa
|
0c79c1bb2b
fix: assert TokenIssuer base32 input length, remove dead pad (SEC_REVIEW F39)
|
před 3 dny |
chiappa
|
41564642cf
docs: mark SEC_REVIEW F38 as fixed in d37890b
|
před 3 dny |
chiappa
|
d37890b68f
fix: rate-limit /login/local even when local admin is disabled (SEC_REVIEW F38)
|
před 3 dny |
chiappa
|
436e670c5a
docs: mark SEC_REVIEW F37 as fixed in f2a81ad
|
před 3 dny |
chiappa
|
f2a81ad611
fix: reject weak local-admin password hash at UI boot (SEC_REVIEW F37)
|
před 3 dny |
chiappa
|
a469e38cb3
docs: mark SEC_REVIEW F36 as fixed in 2c3b65b
|
před 3 dny |
chiappa
|
2c3b65b469
fix: revalidate UI session against api periodically (SEC_REVIEW F36)
|
před 3 dny |
chiappa
|
9b09048f24
docs: mark SEC_REVIEW F35 as fixed in d39ab01
|
před 3 dny |
chiappa
|
d39ab01a7c
fix: validate INTERNAL_JOB_TOKEN entropy at api boot (SEC_REVIEW F35)
|
před 3 dny |
chiappa
|
1409ff2179
docs: mark SEC_REVIEW F34 as fixed in 3a4026b
|
před 4 dny |
chiappa
|
3a4026baf6
fix: log fingerprints, not raw identifiers, in auth flows (SEC_REVIEW F34)
|
před 4 dny |
chiappa
|
6a0aa27c61
docs: mark SEC_REVIEW F33 as fixed in c9f9a45
|
před 4 dny |
chiappa
|
c9f9a45664
fix: accept nullable email on /auth/users/upsert-oidc (SEC_REVIEW F33)
|
před 4 dny |
chiappa
|
e3fa0cc65c
docs: mark SEC_REVIEW F32 as fixed in 0594305
|
před 4 dny |
chiappa
|
05943057b8
fix: batch-load admin IPs list per-row lookups (SEC_REVIEW F32)
|
před 4 dny |
chiappa
|
c8ea0ede68
docs: mark SEC_REVIEW F31 as fixed in 3a2564d
|
před 4 dny |
chiappa
|
3a2564d14b
fix: cap audit-log filter length and pagination depth (SEC_REVIEW F31)
|
před 4 dny |
chiappa
|
6d4687476b
docs: mark SEC_REVIEW F30 as fixed in 2cc1924
|
před 4 dny |
chiappa
|
2cc1924a4e
fix: bound IPs search `q` to anchored IP-shaped prefix (SEC_REVIEW F30)
|
před 4 dny |
chiappa
|
d2e1b3b29c
docs: mark SEC_REVIEW F29 as fixed in a997d65
|
před 4 dny |
chiappa
|
a997d65818
fix: rate-limit /api/v1/admin/* (SEC_REVIEW F29)
|
před 4 dny |
chiappa
|
20c5cce580
docs: mark SEC_REVIEW F28 as fixed in e09964b
|
před 4 dny |