Security
- Credentials embedded in
COUCHDB_URLare now redacted from all logs, at every level — including the rawErrorobjects the sync library logs — souser:pass@hostno longer leaks into container logs (#37). Contributed by @bruno-b-martins.
Fixes
- The static token and the OAuth password/CSRF comparisons hash both sides before the constant-time check, so a non-ASCII
Authorizationheader or a missing password field now returns a clean 401 instead of throwing (previously a malformed 401 withoutWWW-Authenticate, or a 500) (#36). Contributed by @bruno-b-martins. READ_ONLYis now enforced in the vault backend as well as by hiding the write tools, so a write can't slip through a code path that bypasses the tools (#38). Contributed by @bruno-b-martins.
CI
- Workflows run with least-privilege permissions (read-only by default; publish jobs request only what they need), every action is pinned to a commit SHA, oxlint is pinned to a fixed version, and the published image gets a build-provenance attestation; a Dependabot config keeps the pins current (#42). Contributed by @bruno-b-martins.
Docs
SECURITY.mdcorrected to match the code: accurate token-persistence timing and CORS origins, and the metadata-index description now reflects reality (the stale FlexSearch and 50-match-cap text is gone) (#43). Contributed by @bruno-b-martins.