forked from wrenn/wrenn
fix: security hardening from CSO audit
- Add auth failure logging (login, API key, JWT) with IP/email/prefix - Move OAuth JWT from URL params to short-lived cookies to prevent token leakage via browser history, server logs, and Referer headers - Pin Swagger UI to v5.18.2 with SRI integrity hashes - Upgrade Go toolchain to 1.25.8 (fixes 5 called stdlib vulns) - Fix unchecked error in host agent credential refresh - Add .gstack to .gitignore for security report artifacts
This commit is contained in:
@ -1,6 +1,6 @@
|
||||
module git.omukk.dev/wrenn/sandbox/envd
|
||||
|
||||
go 1.25.5
|
||||
go 1.25.8
|
||||
|
||||
require (
|
||||
connectrpc.com/authn v0.1.0
|
||||
|
||||
Reference in New Issue
Block a user