chiappa
|
ce77454c93
fix: never leak exception messages from JsonErrorHandler (SEC_REVIEW F26)
|
há 4 dias atrás |
chiappa
|
5f05743c4b
docs: mark SEC_REVIEW F25 as fixed in 33e9198
|
há 4 dias atrás |
chiappa
|
33e9198800
fix: tighten /internal/* gate to loopback by default (SEC_REVIEW F25)
|
há 4 dias atrás |
chiappa
|
921e17a693
docs: mark SEC_REVIEW F24 as fixed in 193f646
|
há 4 dias atrás |
chiappa
|
193f6463a4
fix: drop CSP unsafe-inline/unsafe-eval via nonces + Alpine CSP build (SEC_REVIEW F24)
|
há 4 dias atrás |
chiappa
|
c67734d80c
docs: mark SEC_REVIEW F23 as fixed in f66ceaf
|
há 5 dias atrás |
chiappa
|
f66ceaf095
fix: tighten openid-connect-php constraint to ^1.0.2 (SEC_REVIEW F23)
|
há 5 dias atrás |
chiappa
|
5a26a19be6
docs: add update workflow to README and an admin manual
|
há 5 dias atrás |
chiappa
|
5232f10cd9
docs: mark SEC_REVIEW F22 as fixed in d9006eb
|
há 5 dias atrás |
chiappa
|
d9006ebae7
fix: build scheduler sidecar from pinned image (SEC_REVIEW F22)
|
há 5 dias atrás |
chiappa
|
63878aa557
docs: mark SEC_REVIEW F21 as fixed in 0da01a8
|
há 5 dias atrás |
chiappa
|
0da01a83d0
fix: strip args from logged stack traces (SEC_REVIEW F21)
|
há 5 dias atrás |
chiappa
|
240ca37e1a
docs: mark SEC_REVIEW F20 as fixed in 1ec9d04
|
há 5 dias atrás |
chiappa
|
1ec9d04008
fix: mount api/ui rootfs read-only at runtime (SEC_REVIEW F20)
|
há 5 dias atrás |
chiappa
|
b1ebe9ca3a
docs: mark SEC_REVIEW F19 as fixed in 96eaa10
|
há 5 dias atrás |
chiappa
|
96eaa10c78
fix: add .dockerignore to api/ui build contexts (SEC_REVIEW F19)
|
há 5 dias atrás |
chiappa
|
8fa6cdd902
docs: mark SEC_REVIEW F18 as fixed in 33179d8
|
há 5 dias atrás |
chiappa
|
33179d8bba
fix: drop container root; run api/ui as uid 1000 (SEC_REVIEW F18)
|
há 5 dias atrás |
chiappa
|
9339948cf1
docs: mark SEC_REVIEW F17 as fixed in 57ab1ba
|
há 5 dias atrás |
chiappa
|
57ab1ba034
fix: audit `GET /auth/users/{id}` lookups to detect enumeration (SEC_REVIEW F17)
|
há 5 dias atrás |
chiappa
|
b8fc612aa6
docs: mark SEC_REVIEW F16 as fixed in 947ab89
|
há 5 dias atrás |
chiappa
|
947ab89e04
fix: bind admin tokens to issuing user; reject after demote/disable (SEC_REVIEW F16)
|
há 5 dias atrás |
chiappa
|
4dab4f8f5a
docs: mark SEC_REVIEW F15 as fixed in 5c15fc5
|
há 5 dias atrás |
chiappa
|
5c15fc5fcf
fix: require confirm:"SEED" on /maintenance/seed-demo (SEC_REVIEW F15)
|
há 5 dias atrás |
chiappa
|
dbbe007f06
docs: mark SEC_REVIEW F14 as fixed in 9849779
|
há 5 dias atrás |
chiappa
|
98497796c9
fix: rate-limit /api/v1/auth/* (SEC_REVIEW F14)
|
há 5 dias atrás |
chiappa
|
2bec88ea2a
docs: mark SEC_REVIEW F13 as fixed in 40be6c1
|
há 5 dias atrás |
chiappa
|
40be6c1875
fix: auto-revoke previous service tokens on rotation (SEC_REVIEW F13)
|
há 5 dias atrás |
chiappa
|
6395be9919
docs: mark SEC_REVIEW F12 as fixed in 4006743
|
há 5 dias atrás |
chiappa
|
400674340e
fix: harden local-admin lookup against is_local-flip tamper (SEC_REVIEW F12)
|
há 5 dias atrás |