2 Commits

Author SHA1 Message Date
df82068aeb fix: CSRF protection, cookie security flags, rate limiting, XSS (#23,#24,#25,#28,#33)
Add CSRF tokens to all cookie-based POST endpoints.
Set Secure and SameSite=Strict on auth cookie.
Rate limit login to 5 attempts per 15min per IP.
Escape HTML in signing error messages (XSS fix).
Remove duplicate get_user_from_cookie definition.
2026-07-04 04:51:56 +00:00
5d417c20e1 Fix setup.sh: add -k flag, NSS import for Fedora, correct trust flags, LibreWolf docs 2026-07-01 04:51:40 +00:00