Repository navigation
Security fixes
Fixed
- Server: Refuses to start if
APP_SECRETis unset or uses a known default placeholder (change-me), preventing CSRF token forgery via publicly known secret - Agent:
self_update_agent()now treats a missing or empty SHA256 from the server as a hard failure instead of silently skipping integrity verification - install-agent.sh: Same fix — aborts with an error if the server returns an empty SHA256 checksum
See CHANGELOG.md for full history.