Commit 502c8a0
catlog22
fix(security): Apply 3 critical security fixes
- sec-001: Add validateAllowedPath to /api/file endpoint (path traversal)
- sec-002: Enable CSRF by default with CCW_DISABLE_CSRF opt-out
- sec-003: Add validateAllowedPath to /api/dialog/browse and /api/dialog/open-file (path traversal)
Ref: fix-17380728000001 parent ed0255b commit 502c8a0
5 files changed
Lines changed: 808 additions & 4 deletions
File tree
- .claude/skills/lite-skill-generator
- templates
- ccw/src/core
- auth
- routes
0 commit comments