You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Security
Reject panel passwords shorter than 12 characters at startup when REQUIRE_LOGIN is enabled, closing an online brute-force path against the
default admin account
Reject unrecognized REQUIRE_LOGIN values (e.g. a typo like Tru) at
startup instead of silently falling back to disabling the login gate
Require SECRET_KEY to be at least 32 characters at startup, blocking a
trivially brute-forceable session-signing secret