This website requires JavaScript.
Explore
Help
Sign In
RunicGateway
/
website
Watch
3
Star
0
Fork
0
You've already forked website
Code
Issues
3
Pull Requests
Actions
Packages
Projects
Releases
Activity
Labels
Milestones
New Issue
3 Open
15 Closed
Label
Show archived labels
Use
alt
+
click/enter
to exclude labels
All labels
No label
bug
duplicate
enhancement
help wanted
invalid
question
severity:critical
severity:high
severity:low
severity:medium
wontfix
bug
duplicate
enhancement
help wanted
invalid
question
wontfix
Milestone
All milestones
No milestones
Project
All projects
No project
Open Projects
API v2 implementation
Closed Projects
Auth upgrades
Author
All users
Assignee
Assigned to nobody
Assigned to anybody
ksfixitman
whitlocktech
wtclaude
Sort
Newest
Oldest
Recently updated
Least recently updated
Most commented
Least commented
Nearest due date
Farthest due date
Label
3 Open
15 Closed
Label
Clear labels
bug
duplicate
enhancement
help wanted
invalid
question
severity:critical
severity:high
severity:low
severity:medium
wontfix
bug
duplicate
enhancement
help wanted
invalid
question
wontfix
Milestone
No milestone
Projects
Clear projects
Open Projects
API v2 implementation
Closed Projects
Auth upgrades
Assignee
Clear assignees
No assignee
ksfixitman
whitlocktech
wtclaude
side ways scrolling section on hero page.
#60
opened
2026-07-14 21:26:45 +00:00
by
ksfixitman
hero page layout
#59
by
ksfixitman
was closed
2026-07-17 09:45:05 +00:00
2
Homepage Teaser
bug
#48
by
whitlocktech
was closed
2026-07-11 16:09:54 +00:00
[SECURITY AUDIT] Username enumeration via login timing side-channel (bcrypt runs only for existing users)
severity:low
#35
opened
2026-07-04 22:02:02 +00:00
by
wtclaude
[SECURITY AUDIT] No Content-Security-Policy — stored-HTML XSS defense rests entirely on sanitization
severity:low
#34
opened
2026-07-04 22:01:47 +00:00
by
wtclaude
[SECURITY AUDIT] Decrypted Discord bot token served from an endpoint on the public API router, guarded only by a shared secret
severity:medium
#33
by
wtclaude
was closed
2026-07-04 22:50:08 +00:00
[SECURITY AUDIT] SSO flow token (sso_tx) validates as a session — token-type confusion in sessionFromDecoded
bug
severity:medium
#32
by
wtclaude
was closed
2026-07-05 02:56:34 +00:00
[SECURITY AUDIT] SSO login bypasses TOTP two-factor for accounts that have 2FA enabled
severity:medium
#31
by
wtclaude
was closed
2026-07-05 03:34:52 +00:00
[SECURITY AUDIT] Session/token revocation is a non-functional stub — logout and password change do not invalidate existing JWTs
bug
severity:medium
#30
by
wtclaude
was closed
2026-07-05 02:08:18 +00:00
On the front page/hero page
enhancement
#25
by
ksfixitman
was closed
2026-07-03 20:01:52 +00:00
enhancement/hero
2
[Bug][Medium] Server boots with no
JWT_SECRET
(only a warning)
bug
#14
by
wtclaude
was closed
2026-07-03 05:58:18 +00:00
[Bug][Medium]
username
unvalidated and not uniqueness-checked on user update
#13
by
wtclaude
was closed
2026-07-03 02:39:44 +00:00
[Security][Medium] Stale JWT: demoted/deleted users keep access until token expiry
#12
by
wtclaude
was closed
2026-07-03 02:32:09 +00:00
[Security][High] Uploaded file extension is attacker-controlled → stored XSS
#11
by
wtclaude
was closed
2026-07-03 02:44:30 +00:00
[Security][High] No role-based authorization —
editor
role is never enforced
#10
by
wtclaude
was closed
2026-07-03 02:31:09 +00:00
Admin path security
#9
by
whitlocktech
was closed
2026-07-03 04:27:53 +00:00
main
wiki editor.
#6
by
ksfixitman
was closed
2026-06-30 18:49:24 +00:00
Hero button bug
#5
by
ksfixitman
was closed
2026-07-03 04:45:27 +00:00