Comment on I built a self-hosted period tracker because I couldn't find one worth using

<- View Parent
terraincognita@lemmy.world ⁨2⁩ ⁨days⁩ ago

No, we didn’t ship it without security hardening.

We already hardened the main sensitive parts:

sealed auth/recovery/reset/flash cookies no auth or recovery secrets in URLs or JSON POST + CSRF logout basic browser security headers CodeQL, gosec, Trivy, and SBOM in CI What’s still missing is a strict CSP. That’s not a one-line switch here because the current frontend still needs some refactoring first.

source
Sort:hotnewtop