Resolve real client IP behind trusted proxies (closes #94)
needs-review
check / check (push) Successful in 2m51s
fix: validate dimensions and fit mode on encrypted URLs (closes #62)
needs-rebase
check / check (push) Successful in 2m30s
feat: blocked_networks config and extended SSRF ranges (closes #67)
needs-review
check / check (push) Successful in 2m28s
Harden http.Server: slowloris timeouts and form body limit (closes #92)
needs-review
check / check (push) Failing after 0s
build: run all linting in Docker via Dockerfile.lint (closes #104)
needs-rework
check / check (push) Failing after 0s
feat: add HSTS, CSP, and Permissions-Policy security headers (closes #91)
needs-review
check / check (push) Successful in 2m48s
Take the image signing key from PIXA_SIGNING_KEY and refuse the example placeholder (closes #110)
needs-review
check / check (push) Failing after 1s
test: cover redirect SSRF and semaphore release in httpfetcher (closes #78)
needs-review
check / check (push) Failing after 1s
next -> main (1.0.0 milestone)
check / check (push) Successful in 2m31s
CSRF protection on the login and URL-generator forms (closes #93)
needs-review
check / check (push) Failing after 1s
feat: include quality and fit in the URL signature (closes #60)
needs-rework
check / check (push) Failing after 1s
fix: script/test conditional-verbose-rerun with -cover (closes #59)
needs-review
check / check (push) Successful in 2m29s
docs: update TODO.md Workflow and Status for the next branching model (closes #106)
needs-review
check / check (push) Successful in 3m23s
next -> main (1.0.0 milestone)
check / check (push) Successful in 4s
feat: cache size management and LRU eviction (closes #51)
merge-ready
check / check (push) Successful in 2m43s
Update golangci-lint to v2.12.2 with canonical config
merge-ready
check / check (push) Successful in 2m49s
feat: validate configuration on startup, fail fast on bad config (closes #52)
merge-ready
check / check (push) Successful in 1m48s
docs: record manual test pass of auth and encrypted URL flows (closes #49)
merge-ready
check / check (push) Successful in 1m34s
fix: set Secure/HttpOnly/SameSite on session cookies (closes #47)
merge-ready
check / check (push) Successful in 1m48s
refactor: extract signature package from imgcache
merge-ready
check / check (push) Successful in 1m38s