Skip to content

Follow up remaining CodeQL security alerts outside #226 #227

Description

@coder13

Follow-up to #226. This issue tracks the remaining active CodeQL findings intentionally outside the targeted password-persistence, API/social rate-limit, and CSRF remediation.\n\nScope:\n- verify CodeQL closes the former user-controlled logout redirect after the CSRF companion change, and investigate only if it remains;\n- replace the permissive CORS configuration in server/index.js with an explicit origin allowlist;\n- add evidence-backed rate limiting for the remaining authorization and filesystem-serving routes (server/auth/index.js, server/index.js) and the server/api/friends.test.js fixture if it remains in CodeQL scope.\n\nAcceptance criteria:\n- every remediation has a focused regression test or runtime verification;\n- CodeQL is rerun and the finding is closed by code, not suppression, dismissal, or query changes;\n- CORS behavior is checked against the deployed frontend/auth callback configuration before production rollout (#176).\n\nDo not broaden this issue into database/schema or email-related work.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions