UNITRONIX
|
c2e0e2e784
|
fix(security): harden CodeQL findings across console and Go server
Address GitHub code scanning alerts with OIDC SSRF guards, confined path
helpers, safer client routing, branding sanitization, upload rate limits,
and CodeQL config exclusions for dev-only and protocol-intentional hashes.
|
2026-06-11 06:57:58 +02:00 |
|
UNITRONIX
|
9b02f06465
|
fix(security): phase-C XSS hardening, path confinement, log redaction
Harden backup restore, theme/attachment paths, frontend escaping, and
sensitive logging without changing normal operator workflows.
|
2026-06-09 03:00:43 +02:00 |
|
UNITRONIX
|
7b938d8c7b
|
fix(security): harden path confinement, SSRF, and shell exec
Add shared safePath helper for file browser, i18n, and backup paths;
use validated OIDC discovery URLs; restrict terminal shells and
network monitor HTTP requests. Remove obsolete one-time i18n migration
scripts already merged into lang/*.json.
|
2026-06-09 02:21:43 +02:00 |
|