Block a user
Gate forwarded-header trust behind trusted-proxy config in rate limiters
Scope note: the PR #83 review found the same unconditional forwarded-header trust in the new PasswordChangeRateLimit (added in commit 8362ce9, shares the postRateLimit helper with `LoginRateLim…
Enforce request body size limit before CSRF middleware parses the form
Archive writer lifecycle: evict writers on webhook deletion and sweep idle archives
Gate forwarded-header trust behind trusted-proxy config in rate limiters
Add admin password change flow (closes #65)
Independent adversarial review (third pass, post-rework)
Verdict: PASS
Reviewed the full diff at head 8362ce9 (both commits, 3084ed5 + 8362ce9) against issue #65, all prior review…
Update golangci-lint to v2.12.2 with canonical config
Implement the database archiving target (closes #43)
Independent adversarial review (third pass) — head 7ca6266
Verdict: FAIL — needs-rework. The code is sound and both previously required changes are genuinely applied and tested; the…
Rate-limit the public webhook receiver endpoint (closes #64)
Independent review of PR #87 (head f32284a)
Verdict: PASS
Definition of done (plan on #64)
- Route-scoped limit only:
setupWebhookRouteswraps/webhook/{uuid}via `s.router.With(s…
Update golangci-lint to v2.12.2 with canonical config
Update golangci-lint to v2.12.2 with canonical config
Update golangci-lint to v2.12.2 with canonical config
Update golangci-lint to v2.12.2 with canonical config