Comment on I built a self-hosted period tracker because I couldn't find one worth using
terraincognita@lemmy.world 2 days agoNo, we didn’t ship it without security hardening.
We already hardened the main sensitive parts:
sealed auth/recovery/reset/flash cookies no auth or recovery secrets in URLs or JSON POST + CSRF logout basic browser security headers CodeQL, gosec, Trivy, and SBOM in CI What’s still missing is a strict CSP. That’s not a one-line switch here because the current frontend still needs some refactoring first.
terraincognita@lemmy.world 1 day ago
CSP is released.