DmitrL-dev
|
5ddfa74771
|
chore: Apply dashboard audit remediations, sync engine counts, update APIs
|
2026-03-27 16:54:18 +10:00 |
|
DmitrL-dev
|
ab55fe2b58
|
fix: make SOC ingest JWT-exempt for sensor access + battle script JWT login
|
2026-03-25 20:14:43 +10:00 |
|
DmitrL-dev
|
62ecc1c7a3
|
sec: fix C4/C5/M4/M5 + domain migration to syntrex.pro
C4: Remove localhost:9100 fallback from 27 dashboard files (use relative URLs)
C5: JWT token_type differentiation (access vs refresh) - middleware rejects refresh as Bearer
M4: Server-side registration gate via SOC_REGISTRATION_OPEN env var
M5: HTML tag stripping on name/org_name fields (XSS prevention)
Domain migration:
- users.go: admin@syntrex.pro
- zerotrust.go: SPIFFE trust domain
- sbom.go: namespace URL
- .env.production.example: all URLs updated
- identity_test.go: test email
|
2026-03-24 11:49:33 +10:00 |
|
DmitrL-dev
|
8d87c453b0
|
feat: add free starter plan with 1000 scans/month quota tracking
|
2026-03-24 09:37:09 +10:00 |
|
DmitrL-dev
|
a120aa2750
|
fix: add /api/v1/scan to JWT public paths (demo scanner bypass auth)
|
2026-03-23 20:32:11 +10:00 |
|
DmitrL-dev
|
41cbfd6e0a
|
Release prep: 54 engines, self-hosted signatures, i18n, dashboard updates
|
2026-03-23 16:45:40 +10:00 |
|