
bvandeusenandClaude Sonnet 4.6
00643c778e
security: fix 10 vulnerabilities from security audit
- SSRF: block private/internal URLs in image cache fetch
- SSRF: block private/internal URLs in RSS feed fetch (scheme guard)
- SSRF: block private/internal URLs in CalDAV URL setting
- Auth: require login for GET /api/images/<id> (was unauthenticated)
- Auth: restrict Ollama model pull/delete to admin users only
- Info disclosure: remove email from /api/users/search response
- OAuth: skip email-based account linking when email_verified is false
- Config: raise hard error on default SECRET_KEY when SECURE_COOKIES=true
- Rate limit: document proxy header requirement; add startup warning
- XSS: remove src/alt from global DOMPurify ADD_ATTR allowlist
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-29 00:37:13 -04:00
..
2026-02-09 23:35:44 -05:00
2026-03-28 00:51:24 -04:00
2026-03-10 15:07:00 -04:00
2026-03-25 20:17:51 -04:00
2026-03-10 15:18:22 -04:00
2026-03-07 23:15:01 -05:00
2026-03-06 15:26:34 -05:00
2026-03-09 23:32:21 -04:00
2026-03-06 14:02:54 -05:00
2026-03-25 20:06:09 -04:00
2026-03-07 23:15:01 -05:00
2026-03-05 13:05:26 -05:00
2026-03-11 10:57:02 -04:00
2026-03-02 20:52:21 -05:00
2026-03-10 22:39:05 -04:00
2026-03-11 15:37:00 -04:00
2026-03-11 15:37:00 -04:00
2026-02-11 06:49:12 -05:00
2026-02-09 23:35:44 -05:00
2026-03-02 20:52:21 -05:00
2026-03-28 00:51:36 -04:00
2026-03-04 08:39:49 -05:00
2026-03-29 00:37:13 -04:00
2026-03-28 00:51:36 -04:00
2026-02-11 21:24:35 -05:00
2026-02-14 08:46:51 -05:00
2026-03-07 18:46:08 -05:00
2026-03-10 18:34:52 -04:00
2026-03-28 00:38:04 -04:00
2026-03-07 23:15:01 -05:00
2026-03-09 21:30:55 -04:00
2026-03-07 23:15:01 -05:00
2026-03-25 15:39:13 -04:00
2026-02-18 20:43:47 -05:00
2026-03-11 16:56:30 -04:00
2026-03-26 17:37:27 -04:00
2026-03-07 23:15:01 -05:00
2026-03-10 23:51:17 -04:00
2026-03-10 23:51:17 -04:00