Joseph Doherty
3b3760f026
docs(code-reviews): re-review batch 3 at 39d737e — Host, InboundAPI, ManagementService, NotificationService, Security
...
21 new findings: Host-012..015, InboundAPI-014..017, ManagementService-014..017, NotificationService-014..018, Security-012..015.
2026-05-17 00:48:25 -04:00
Joseph Doherty
84a696b0e4
fix(security): resolve Security-009,010,011 — LDAP connection timeout, design-doc correction, security-path test coverage; Security-008 deferred
2026-05-16 22:24:03 -04:00
Joseph Doherty
30ebbdd183
fix(security): resolve Security-004..007 — configurable user-id attribute, DN escaping, JWT issuer/audience validation, idle-timeout preservation
2026-05-16 21:22:01 -04:00
Joseph Doherty
0d9363766d
fix(security): resolve Security-001/002/003 — reachable StartTLS path, Secure cookie, JWT signing key validation
2026-05-16 19:47:17 -04:00
Joseph Doherty
977d7369a7
docs: add code review process and baseline review of all 19 modules
...
Establishes a per-module code review workflow under code-reviews/ and
records the 2026-05-16 baseline review (commit 9c60592 ): 241 findings
across all src/ modules (6 Critical, 46 High, 100 Medium, 89 Low).
This is the clean starting point for remediation work.
2026-05-16 18:09:09 -04:00