Block a user
[SECURITY AUDIT] No Content-Security-Policy — stored-HTML XSS defense rests entirely on sanitization
[SECURITY AUDIT] Decrypted Discord bot token served from an endpoint on the public API router, guarded only by a shared secret
[SECURITY AUDIT] SSO flow token (sso_tx) validates as a session — token-type confusion in sessionFromDecoded
[SECURITY AUDIT] SSO login bypasses TOTP two-factor for accounts that have 2FA enabled
[SECURITY AUDIT] Session/token revocation is a non-functional stub — logout and password change do not invalidate existing JWTs
Add Discord bot: moderation, filters, scheduling, roles, invites, site integration
Hero editor: fullscreen landing, remove two-card row, quick links into hero
wtclaude
pushed to feature/hero-fullscreen-landing at RunicGateway/website
2026-07-04 02:49:52 +00:00
wtclaude
created branch feature/hero-fullscreen-landing in RunicGateway/website
2026-07-04 02:49:51 +00:00
Add Swagger/OpenAPI API docs (swagger-ui + swagger-autogen)
Hero editor: scale text-block fonts with the resize handle (#25)
Add session abstraction, mobile bearer auth, and pluggable SSO (Google/Discord/OIDC)
wtclaude
created branch feature/auth-session-abstraction in RunicGateway/website
2026-07-03 15:31:42 +00:00
wtclaude
pushed to feature/auth-session-abstraction at RunicGateway/website
2026-07-03 15:31:42 +00:00
Add Bot Activity admin panel: banned-IP view + recent events + emergency unban