Skip to content

Complete security and abuse-resistance launch review #139

Description

@zaridan

Review the public core before inviting external operators. Acceptance: auth/session behavior, webhook SSRF protection, secret handling, OAuth scopes, inbound spoofing/forgery behavior, rate limits, attachment handling, and security docs are reviewed with explicit follow-ups.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:launchLaunch readiness, docs, polish, and release blockersarea:securitySecurity posture, secrets, access, and abuse resistancepriority:p1Important near-term worktype:taskPlanned implementation task

    Type

    No type

    Projects

    Status
    Todo

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions