v1.0.9 — Security Hardening and Shared Rate Limiting
This release focuses on security hardening, safer production defaults, and more resilient request throttling.
Highlights
- Added stronger production startup checks for insecure default or weak secrets
- Introduced optional
FORCE_HTTPSand safer production behavior around transport security - Disabled OpenAPI exposure by default in production unless explicitly enabled
- Removed legacy Telegram OAuth polling token support via query string
- Added
Cache-Control: no-storefor API responses handling sensitive data - Strengthened sensitive-action protection for destructive account and admin operations
- Added Redis-backed shared rate limiting with in-memory fallback for local and degraded scenarios
- Hardened Telegram bot token handling
- Expanded CI with secret scanning and dependency audit jobs
- Added regression tests for security-sensitive flows
Operational Notes
- Replace placeholder values for
JWT_SECRET,COOKIE_SECRET, andENCRYPTION_KEYbefore production deploy - If needed, generate secrets with
openssl rand -hex 32 OPENAPI_ENABLEDshould remain disabled in production unless explicitly required- Docker Compose now defaults to Redis-backed rate limiting via the internal Redis service
Versioning
This is a patch release under the current versioning policy because it improves security and deployment safety without introducing intended breaking changes.
Full Changelog: v1.0.8...v1.0.9