Matthew Meszaros
|
3de01f25b3
|
feat: gate MCP and /ai/tools per tool for keys and tokens, with AI_AGENT on the web and playbook tools, and require use_ai for member sessions on /ai/tools
|
2026-10-04 05:21:18 -07:00 |
|
Matthew Meszaros
|
5d4b0ad6e5
|
feat: hold the invite_member, update_member_role and rotate_webhook_secret AI tools to the same recent confirmation their REST routes require, answering reauth_required on /ai/tools and refusing them where no confirmed session exists
|
2026-10-04 05:14:30 -07:00 |
|
Matthew Meszaros
|
886756ae0f
|
feat: share one api_key_mailbox_limited code and keyMailboxLimited check across the campaign, AI tool and MCP handlers
|
2026-10-04 03:43:26 -07:00 |
|
Matthew Meszaros
|
497f58bb5a
|
feat: hold a mailbox-limited API key to explicit sender lists of its own mailboxes when it creates, edits or starts a campaign, and refuse it on /ai/tools and /mcp, which act across the workspace, with api_key_mailbox_limited
|
2026-10-04 03:24:25 -07:00 |
|
Matthew Meszaros
|
bf47984cd5
|
feat: cap every OAuth grant and API key at the delegating member's role (consent narrows scopes and reports the withheld ones, tokens re-check the member's current role at every gate and MCP tool, keys stay within their creator's permissions, mailboxes and IP allowlist), keep OAuth tokens off API key and OAuth app management, require a fresh sign-in to approve an app, revoke a grant whose refresh token is presented twice, count only unexpired grants as installs, seal app webhook secrets under the instance key, name the workspace and flag unverified apps on the consent screen, and let credential managers list and revoke every member's app authorizations
|
2026-10-04 02:59:10 -07:00 |
|
Matthew Meszaros
|
610d511307
|
feat: answer every server-side failure in admin, internal, webhook, warmup routing, Stripe webhook, agent tool and MCP handlers with the fixed internal error and log the detail against the request id, keep correctable webhook and routing refusals as typed errors with their own messages, drop the request URL from MillionVerifier transport errors so the API key never reaches a log or response, and redact :code path parameters in the access log
|
2026-10-04 02:57:17 -07:00 |
|
Matthew Meszaros
|
e668a2a36b
|
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
|
2026-09-19 08:18:35 +02:00 |
|
Matthew Meszaros
|
49acd51b64
|
feat: stop one recurring fault burying error tracking by reporting it once per five minutes with the count it stands for, keep a cache outage from answering every signed-in request with a 500 and from taking realtime down by treating an unreachable Redis as a miss and the websocket handshake nonce nothing reads as best-effort, answer a 5xx with a sentence the reader can act on while the call site's own words go to the log against the same request id, prefer the API's own message over the HTTP class in the admin and dashboard clients, and name the fix on a schema registry refusal, an SES sandbox rejection and a mailbox check that could not be run
|
2026-09-19 07:39:40 +02:00 |
|
Matthew Meszaros
|
d6ddf1f170
|
feat: fix implicit-TLS SMTP on 465 and IMAP STARTTLS on 143 behind a stored per-mailbox security mode that accepts any port, stop worker ID churn orphaning mailbox assignments via flock-claimed persistent worker ids, give the unibox a standard mail-folder sidebar (inbox/sent/drafts/archive/spam/trash) backed by a provider-derived folder column, and expose the AI tool registry over REST for non-MCP function-calling agents (#283)
|
2026-09-01 03:53:19 -07:00 |
|