You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Added separate GitHub OAuth flows for web and mobile clients, including dedicated routes, handlers, client configuration, callback handling, and refresh/logout behavior.
Added PKCE-based OAuth security with high-entropy state values, one-time mobile app codes, and app-state round-tripping for mobile login validation.
Added persisted, opaque refresh tokens with HMAC hashing, rotation, family revocation on reuse, transactional updates, and separate web/mobile refresh flows.
Added stronger API token storage using hashed lookup values and AES-GCM encrypted token storage.
Added database indexes for refresh tokens, mobile app login codes, and GitHub profile uniqueness.
Added support for multiple allowed GitHub login emails via LIMIT_TO_USER_EMAILS.
Bugfixes And Security Fixes
Hardened startup validation for JWT, cookie, OAuth, API-token, and production CORS configuration.
Tightened JWT validation, enforced access-token usage, fixed signing to HS512, and required web JWT identity to match the authenticated session.
Reduced sensitive logging, removed plaintext API token exposure, avoided Gin default request logging, and added request body size limits.
Fixed mobile refresh, web refresh cookie scoping, OAuth callback cleanup, and refresh-token logout revocation behavior.
Improved internal service reliability with bounded HTTP calls, status checks, path escaping, correct request contexts, and safer MongoDB transaction boundaries.
Fixed profile API token rotation so updated credentials propagate to profiles, sensors, controllers, online state, and FCM mappings.
Go Improvements
Refactored authentication, OAuth, JWT, PKCE, cookie, random, and session logic into clearer, more idiomatic Go modules.
Cleaned up common correctness issues around error handling, context usage, type assertions, cursor cleanup, loop variables, deferred resources, timestamp handling, and ObjectID comparisons.
Test Improvements
Hardened make test with protobuf generation, vet, shadow checks, staticcheck, race-enabled tests, and coverage generation.
Added startup validator unit coverage for valid configuration, missing OAuth secrets, short cookie secrets, and production CORS refusal.