Dorian
d7c9f4917a
docs: add security audit report for new features (Task 22)
Audited cloud file upload, AIUI iframe, context broker, FileBrowser
proxy, and RPC endpoints. Key findings:
- XSS: safe (Vue template escaping)
- Context broker: properly validates origins
- FileBrowser: medium risk path traversal (client-side), token in URLs
- CSRF: high risk (no tokens, but mitigated by JSON content type)
- Nginx: missing security headers
Full report: docs/security-audit-2026-03-05.md
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 08:49:22 +00:00
..
2026-01-24 22:01:51 +00:00
2026-02-01 02:22:02 +00:00
2026-02-03 21:43:33 +00:00
2026-02-03 21:43:33 +00:00
2026-02-01 02:22:02 +00:00
2026-01-24 22:59:20 +00:00
2026-01-24 22:59:20 +00:00
2026-01-24 22:59:20 +00:00
2026-03-02 08:34:13 +00:00
2026-02-01 18:46:35 +00:00
2026-03-05 08:49:22 +00:00
2026-02-17 15:03:34 +00:00
2026-02-01 18:46:35 +00:00
2026-03-04 05:23:42 +00:00
2026-02-01 18:46:35 +00:00
2026-02-17 15:03:34 +00:00