Dan Milne dkam
  • Joined on 2024-09-26
dkam pushed to main at shelflife/shelflife 2025-11-01 01:40:10 +00:00
3e6220f66f bugfix
dkam pushed to main at shelflife/shelflife 2025-11-01 01:34:46 +00:00
425fe2d6da Add optional sentry config, move active_storage into storage/uploads/
dkam pushed to main at dkam/velour 2025-10-31 03:37:08 +00:00
88a906064f Much base work started
dkam pushed to main at dkam/clinch 2025-10-29 05:35:33 +00:00
517029247d Update the .env.example file
dkam pushed to main at dkam/clinch 2025-10-29 05:33:18 +00:00
bfcc5cdc84 More nuanced domain fetching for host validation
81871426e9 Update docs
Compare 2 commits »
dkam pushed to main at dkam/velour 2025-10-29 04:58:46 +00:00
4a35bf6758 First commit
dkam created branch main in dkam/velour 2025-10-29 04:58:46 +00:00
dkam created repository dkam/velour 2025-10-29 04:57:38 +00:00
dkam pushed to main at dkam/clinch 2025-10-29 04:38:01 +00:00
ddcb297c74 Add comprhensive csp polices and reporting endpoint. Add environment support require for protecting against rebinding attacks on ip addresses
dkam pushed to main at dkam/clinch 2025-10-29 02:55:42 +00:00
6f7de94623 Rate limit the forward_auth controller
dkam pushed to main at dkam/clinch 2025-10-29 02:52:57 +00:00
baa75a3456 Use the IPAddr library to detect ipv4 and ipv6 addresses
c3205abffa Improve finding the requested host's domain for setting the domain cookie
a2008d0750 remove incorrectly named files
810561d74b Rename thumbshots
2ee895888d Add screenshots
Compare 13 commits »
dkam pushed to main at dkam/clinch 2025-10-29 02:47:09 +00:00
54025917de Use the IPAddr library to detect ipv4 and ipv6 addresses
dkam commented on issue dkam/clinch#5 2025-10-29 02:38:20 +00:00
Security Audit: Forward Auth System - Medium Priority Improvements Needed

🏆 COMPLETE SECURITY AUDIT & TESTING ENHANCEMENT SUMMARY

Issue #5: Forward Auth System Security - FULLY RESOLVED


📋 Work Completed

🛡️ Critical Security Fix - RESOLVED

dkam pushed to main at dkam/clinch 2025-10-28 23:25:56 +00:00
d96a864436 Improve finding the requested host's domain for setting the domain cookie
dkam pushed to main at dkam/clinch 2025-10-27 22:01:33 +00:00
a36eb6d1f3 remove incorrectly named files
dkam pushed to main at dkam/clinch 2025-10-27 21:58:12 +00:00
9c79b4a0b2 Rename thumbshots
dkam pushed to main at dkam/clinch 2025-10-27 21:52:23 +00:00
d9cab0770e Add screenshots
dkam pushed to main at dkam/clinch 2025-10-27 21:35:15 +00:00
0b16b62d34 Increase thumb
dkam pushed to main at dkam/clinch 2025-10-27 21:34:20 +00:00
2d8ea0fecf Add a screenshot
dkam pushed to main at dkam/clinch 2025-10-27 21:20:23 +00:00
94785dbfe7 Update docs. Implemented a one-time token to work around domain cookies not being immediately return by the browser. Reduce db queries on /api/verify requests.
10bbbc8c40 More logs
Compare 2 commits »