Security
- Fixed all 17 admin and DPO console pages being served to any HTTP client with no server-side login check - the client-side JavaScript redirect wasn't backed by a server-side gate, so a plain curl request received the full page source (internal API endpoints, function names, request schemas) with no credentials. Console pages now require a valid server-side session, set via a new login cookie kept separate from the existing API bearer token.
Reported by VulDB: Client-Side-Only Authentication Allows Complete Bypass, Missing Authentication on All Admin and DPO Console Pages.
- Fixed the first-run Super-Admin setup endpoint (/api/v1/bootstrap/setup) accepting unauthenticated requests indefinitely - a fresh or reset deployment could have its admin account claimed by whoever reached the endpoint first. Setup now requires a deployment-configured TSI_BOOTSTRAP_TOKEN (see the README), and directory listing on the setup path, which disclosed its existence, is disabled.
Reported by VulDB: Unauthenticated Super-Admin Bootstrap Endpoint.