github engels74/obzorarr 0.1.4
v0.1.4

latest releases: 0.1.10, 0.1.9, 0.1.8...
2 months ago

Security

  • Hardened application against common attack vectors (#10)
    • Added request filtering to block vulnerability scanner probes (.env, .git, wp-*, phpmyadmin, etc.)
    • Implemented global rate limiting with route-specific configurations (auth: 10/5min, API: 30/min, default: 60/min)
    • Added security headers: X-Frame-Options, HSTS, X-Content-Type-Options
    • Fixed cookie secure flag for production environments
    • Removed GET logout endpoint to prevent CSRF attacks
    • Sanitized error messages in onboarding endpoints

Full Changelog: v0.1.3...v0.1.4

Don't miss a new obzorarr release

NewReleases is sending notifications on new releases.