Block a user
harden: verify all approval fields and make failed signing retryable (closes #174)
FAIL — needs-rework. A constructible bypass defeats the module's central guarantee.
1. BLOCKING: an EIP-7702 type-4 artifact passes verification and takes over the account
`src/shared/appro…
clawbot
deleted branch issue-90-body-limit-before-csrf from sneak/webhooker
2026-08-11 14:37:42 +02:00
clawbot
pushed to fix/issue-212-utc-checkbox-placement at sneak/AutistMask
2026-08-11 14:37:41 +02:00
clawbot
created branch fix/issue-212-utc-checkbox-placement in sneak/AutistMask
2026-08-11 14:37:41 +02:00
Enforce request body size limit before CSRF middleware parses the form
Enforce the body size limit before CSRF parses the form (closes #90)
Slack webhook credential still leaks via delivery errors, SSRF logs, and the source_logs template data
Source detail page renders raw target config, exposing the Slack webhook URL credential
Mask target config on the source detail page (closes #113)
Enforce the body size limit before CSRF parses the form (closes #90)
PASS at a46ce96 — cap precedes CSRF in all four form route groups (the only groups reaching a form-parsing handler), the rebase changed nothing observable beyond the test-only noopEvictor…
RetentionDays cannot be set to 0 (retain forever) via the normal create path
Allow retention_days of 0 to mean retain forever (closes #79)
Mask target config on the source detail page (closes #113)
PASS — masking, the no-raw-field projection, the fail-closed paths, tests, single commit on next, make fmt/lint/test all verified; cache-defeated `docker build --no-cache-filter=lint,build…
Allow retention_days of 0 to mean retain forever (closes #79)
PASS — rebase onto next (c93d974) is behaviour-neutral; the seedWebhook collision is correctly resolved, CI is green on the head commit (4m44s), and lint (0 issues) and tests (all 8…
clawbot
pushed to chore/issue-166-policy-compliance-sweep at sneak/AutistMask
2026-08-11 14:34:36 +02:00