jevb
a0fd5e8fda
security: fix 11 vulnerabilities from security review
Batch 1 — Immediate priority:
- C4: Atomic voice channel capacity (JoinVoiceChannelIfCapacity)
- H5: Sanitize emoji field with bluemonday (stored XSS)
- H8: Permission check before FTS search (timing oracle)
- M8: Filter ready payload channels by ReadMessages
- H10: Remove password/TOTP from admin ListAllUsers query
Batch 2 — Next sprint:
- C1: TOTP replay prevention (UsedTOTPCodeStore, 90s TTL)
- C2: Per-user TOTP brute-force rate limit (10/15min)
- C3: Delete requires SendMessages or ManageMessages
- H1: Expired sessions deleted on detection
- H3: Bearer token whitespace trimmed
- H6: Log warning when WS origin checking disabled
2026-03-31 19:10:42 +02:00
..
2026-03-31 16:27:21 +02:00
2026-03-31 19:08:02 +02:00
2026-03-17 04:11:04 +01:00
2026-03-31 18:47:06 +02:00
2026-03-31 19:10:42 +02:00
2026-03-31 16:27:21 +02:00
2026-03-19 06:20:00 +01:00
2026-03-15 07:07:59 +01:00
2026-03-17 04:11:04 +01:00
2026-03-31 16:27:21 +02:00
2026-03-29 12:35:04 +02:00
2026-03-28 10:39:23 +01:00
2026-03-31 19:00:17 +02:00
2026-03-31 16:27:21 +02:00
2026-03-24 21:30:23 +01:00
2026-03-31 19:00:17 +02:00
2026-03-29 00:51:54 +01:00
2026-03-29 12:35:04 +02:00
2026-03-29 21:31:18 +02:00
2026-03-31 16:27:21 +02:00
2026-03-29 00:51:54 +01:00
2026-03-31 16:27:21 +02:00
2026-03-31 19:10:42 +02:00
2026-03-29 19:39:22 +02:00
2026-03-31 19:00:17 +02:00
2026-03-31 19:08:02 +02:00
2026-03-31 16:27:21 +02:00
2026-03-31 19:08:02 +02:00