fix: harden SAC security per audit (0.4.15)

Close audit findings: anti-spoof client IP for login rate limit, JWT/CORS
enforce on startup, SSH host-key verification and sudo via stdin, optional
WinRM HTTPS, SSE httpOnly cookie auth, ingest body limit, ILIKE escaping,
and HMAC API key hashing with legacy SHA-256 fallback.
This commit is contained in:
PTah
2026-07-07 19:32:12 +10:00
parent 939fe122c5
commit 80320ae698
29 changed files with 452 additions and 160 deletions
+2 -2
View File
@@ -1,4 +1,4 @@
<template>
<template>
<div class="overview-page">
<h1>Обзор</h1>
@@ -556,7 +556,7 @@ function connectLive() {
eventSource?.close();
const url = `/api/v1/stream/events?token=${encodeURIComponent(token)}`;
const url = `/api/v1/stream/events`;
eventSource = new EventSource(url);