Commit Verlauf

Autor SHA1 Nachricht Datum
  chiappa 0c79c1bb2b fix: assert TokenIssuer base32 input length, remove dead pad (SEC_REVIEW F39) vor 3 Tagen
  chiappa 41564642cf docs: mark SEC_REVIEW F38 as fixed in d37890b vor 3 Tagen
  chiappa d37890b68f fix: rate-limit /login/local even when local admin is disabled (SEC_REVIEW F38) vor 3 Tagen
  chiappa 436e670c5a docs: mark SEC_REVIEW F37 as fixed in f2a81ad vor 3 Tagen
  chiappa f2a81ad611 fix: reject weak local-admin password hash at UI boot (SEC_REVIEW F37) vor 3 Tagen
  chiappa a469e38cb3 docs: mark SEC_REVIEW F36 as fixed in 2c3b65b vor 3 Tagen
  chiappa 2c3b65b469 fix: revalidate UI session against api periodically (SEC_REVIEW F36) vor 3 Tagen
  chiappa 9b09048f24 docs: mark SEC_REVIEW F35 as fixed in d39ab01 vor 3 Tagen
  chiappa d39ab01a7c fix: validate INTERNAL_JOB_TOKEN entropy at api boot (SEC_REVIEW F35) vor 3 Tagen
  chiappa 1409ff2179 docs: mark SEC_REVIEW F34 as fixed in 3a4026b vor 3 Tagen
  chiappa 3a4026baf6 fix: log fingerprints, not raw identifiers, in auth flows (SEC_REVIEW F34) vor 3 Tagen
  chiappa 6a0aa27c61 docs: mark SEC_REVIEW F33 as fixed in c9f9a45 vor 3 Tagen
  chiappa c9f9a45664 fix: accept nullable email on /auth/users/upsert-oidc (SEC_REVIEW F33) vor 3 Tagen
  chiappa e3fa0cc65c docs: mark SEC_REVIEW F32 as fixed in 0594305 vor 3 Tagen
  chiappa 05943057b8 fix: batch-load admin IPs list per-row lookups (SEC_REVIEW F32) vor 3 Tagen
  chiappa c8ea0ede68 docs: mark SEC_REVIEW F31 as fixed in 3a2564d vor 3 Tagen
  chiappa 3a2564d14b fix: cap audit-log filter length and pagination depth (SEC_REVIEW F31) vor 3 Tagen
  chiappa 6d4687476b docs: mark SEC_REVIEW F30 as fixed in 2cc1924 vor 3 Tagen
  chiappa 2cc1924a4e fix: bound IPs search `q` to anchored IP-shaped prefix (SEC_REVIEW F30) vor 3 Tagen
  chiappa d2e1b3b29c docs: mark SEC_REVIEW F29 as fixed in a997d65 vor 4 Tagen
  chiappa a997d65818 fix: rate-limit /api/v1/admin/* (SEC_REVIEW F29) vor 4 Tagen
  chiappa 20c5cce580 docs: mark SEC_REVIEW F28 as fixed in e09964b vor 4 Tagen
  chiappa e09964b4ad fix: bound RateLimiter bucket map with LRU eviction (SEC_REVIEW F28) vor 4 Tagen
  chiappa 8e7a5f7b46 docs: mark SEC_REVIEW F27 as fixed in 060119a vor 4 Tagen
  chiappa 060119af27 fix: rate-limit pre-auth and unauthenticated paths (SEC_REVIEW F27) vor 4 Tagen
  chiappa 5072c54f87 docs: mark SEC_REVIEW F26 as fixed in ce77454 vor 4 Tagen
  chiappa ce77454c93 fix: never leak exception messages from JsonErrorHandler (SEC_REVIEW F26) vor 4 Tagen
  chiappa 5f05743c4b docs: mark SEC_REVIEW F25 as fixed in 33e9198 vor 4 Tagen
  chiappa 33e9198800 fix: tighten /internal/* gate to loopback by default (SEC_REVIEW F25) vor 4 Tagen
  chiappa 921e17a693 docs: mark SEC_REVIEW F24 as fixed in 193f646 vor 4 Tagen