This website requires JavaScript.
Explore
Help
Sign In
RunicGateway
/
website
Watch
3
Star
0
Fork
0
You've already forked website
Code
Issues
3
Pull Requests
Actions
Packages
Projects
Releases
Activity
Labels
Milestones
New Issue
0 Open
4 Closed
Label
Show archived labels
Use
alt
+
click/enter
to exclude labels
All labels
No label
bug
duplicate
enhancement
help wanted
invalid
question
severity:critical
severity:high
severity:low
severity:medium
wontfix
bug
duplicate
enhancement
help wanted
invalid
question
wontfix
Milestone
All milestones
No milestones
Project
All projects
No project
Open Projects
API v2 implementation
Closed Projects
Auth upgrades
Author
All users
Assignee
Assigned to nobody
Assigned to anybody
ksfixitman
whitlocktech
wtclaude
Sort
Newest
Oldest
Recently updated
Least recently updated
Most commented
Least commented
Nearest due date
Farthest due date
Label
0 Open
4 Closed
Label
Clear labels
bug
duplicate
enhancement
help wanted
invalid
question
severity:critical
severity:high
severity:low
severity:medium
wontfix
bug
duplicate
enhancement
help wanted
invalid
question
wontfix
Milestone
No milestone
Projects
Clear projects
Open Projects
API v2 implementation
Closed Projects
Auth upgrades
Assignee
Clear assignees
No assignee
ksfixitman
whitlocktech
wtclaude
[SECURITY AUDIT] Decrypted Discord bot token served from an endpoint on the public API router, guarded only by a shared secret
severity:medium
#33
by
wtclaude
was closed
2026-07-04 22:50:08 +00:00
[SECURITY AUDIT] SSO flow token (sso_tx) validates as a session — token-type confusion in sessionFromDecoded
bug
severity:medium
#32
by
wtclaude
was closed
2026-07-05 02:56:34 +00:00
[SECURITY AUDIT] SSO login bypasses TOTP two-factor for accounts that have 2FA enabled
severity:medium
#31
by
wtclaude
was closed
2026-07-05 03:34:52 +00:00
[SECURITY AUDIT] Session/token revocation is a non-functional stub — logout and password change do not invalidate existing JWTs
bug
severity:medium
#30
by
wtclaude
was closed
2026-07-05 02:08:18 +00:00