
bvandeusenandClaude Sonnet 4.6
00643c778e
security: fix 10 vulnerabilities from security audit
- SSRF: block private/internal URLs in image cache fetch
- SSRF: block private/internal URLs in RSS feed fetch (scheme guard)
- SSRF: block private/internal URLs in CalDAV URL setting
- Auth: require login for GET /api/images/<id> (was unauthenticated)
- Auth: restrict Ollama model pull/delete to admin users only
- Info disclosure: remove email from /api/users/search response
- OAuth: skip email-based account linking when email_verified is false
- Config: raise hard error on default SECRET_KEY when SECURE_COOKIES=true
- Rate limit: document proxy header requirement; add startup warning
- XSS: remove src/alt from global DOMPurify ADD_ATTR allowlist
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-29 00:37:13 -04:00
..
2026-03-28 13:21:30 -04:00
2026-03-25 13:38:09 -04:00
2026-03-25 17:44:39 -04:00
2026-02-13 21:42:45 -05:00
2026-03-10 18:34:52 -04:00
2026-03-26 22:43:59 -04:00
2026-02-25 20:12:13 -05:00
2026-02-22 21:30:08 -05:00
2026-03-28 00:51:24 -04:00
2026-03-11 16:56:30 -04:00
2026-03-10 22:39:05 -04:00
2026-03-11 15:37:00 -04:00
2026-03-26 22:43:59 -04:00
2026-03-24 00:42:01 -04:00
2026-02-14 08:46:51 -05:00
2026-02-12 17:49:22 -05:00
2026-02-13 21:42:45 -05:00
2026-03-29 00:37:13 -04:00
2026-03-11 15:37:00 -04:00
2026-03-28 00:51:36 -04:00
2026-03-28 00:51:36 -04:00
2026-03-28 00:51:36 -04:00
2026-02-19 16:43:41 -05:00
2026-03-12 18:02:28 -04:00