-
Notifications
You must be signed in to change notification settings - Fork 6
Pull requests: abeggled/openbridgeserver
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[Codex] security: reject active/scriptable SVGs on icon import (prevent stored XSS)
Security
Security-related changes
#558
opened May 26, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix(frontend): sanitize inline SVG icon content before v-html render
Security
Security-related changes
#557
opened May 26, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix(security): sanitize SVG icons before ValueDisplay injection
Security
Security-related changes
#556
opened May 26, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix(security): sanitize SVG uploads and restrict icon import to admins
Security
Security-related changes
#555
opened May 26, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix(config): preserve legacy OPENTWS envs and DB path to avoid rebrand-first-boot
Security
Security-related changes
#554
opened May 26, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix(auth): require authentication for datapoint value reads and websocket connections
Security
Security-related changes
#553
opened May 26, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix(history): deny unknown page IDs in access check
Security
Security-related changes
#552
opened May 26, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix(frontend): sanitize markdown HTML rendering in Text widget
Security
Security-related changes
#551
opened May 26, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix(logic): block private-network SSRF in api_client node
Security
Security-related changes
#532
opened May 20, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix: harden AST sandboxing in logic executor to prevent sandbox escapes
Security
Security-related changes
#528
opened May 20, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix(logic): harden formula eval against sandbox escape
Security
Security-related changes
#527
opened May 20, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix(auth): require admin for adapter config and binding mutations
Security
Security-related changes
#521
opened May 19, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix(security): restrict config export/import to admins
Security
Security-related changes
#503
opened May 17, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix(logic): restrict graph mutation/run endpoints to admin users
Security
Security-related changes
#502
opened May 17, 2026 by
Micsi
Collaborator
Loading…
[Codex] fix(auth): restore admin-only access for datapoint and logic mutations
Security
Security-related changes
#501
opened May 17, 2026 by
Micsi
Collaborator
Loading…
ProTip!
Type g p on any issue or pull request to go back to the pull request listing page.