Skip to content

v0.1.2 — Security Hardening

Latest

Choose a tag to compare

@dreamnight16 dreamnight16 released this 05 Jun 07:04
· 24 commits to main since this release

Security Fixes

HIGH

  • Make API auth token REQUIRED (was optional — API was open)
  • Remove unsafe-eval from production CSP

MEDIUM

  • Add CSRF Origin header check for POST/PUT/DELETE
  • Cap rate limiter map size to prevent memory exhaustion