catlog22
502c8a09a1
fix(security): Apply 3 critical security fixes
- sec-001: Add validateAllowedPath to /api/file endpoint (path traversal)
- sec-002: Enable CSRF by default with CCW_DISABLE_CSRF opt-out
- sec-003: Add validateAllowedPath to /api/dialog/browse and /api/dialog/open-file (path traversal)
Ref: fix-1738072800000
2026-01-28 22:04:18 +08:00
..
2026-01-28 22:04:18 +08:00
2026-01-28 22:04:18 +08:00
2026-01-13 18:20:54 +08:00
2026-01-07 22:35:46 +08:00
2026-01-07 22:35:46 +08:00
2026-01-07 21:51:26 +08:00
2026-01-07 22:35:46 +08:00
2026-01-07 22:35:46 +08:00
2026-01-28 08:26:37 +08:00
2026-01-16 13:33:38 +08:00
2025-12-16 19:27:05 +08:00
2025-12-22 20:17:38 +08:00
2026-01-15 15:20:20 +08:00
2025-12-17 23:47:49 +08:00
2026-01-22 15:41:01 +08:00
2025-12-16 19:27:05 +08:00
2026-01-28 19:57:24 +08:00
2025-12-21 23:28:19 +08:00
2025-12-14 12:11:29 +08:00
2026-01-21 22:55:24 +08:00