Commit Graph
5 Commits
Author SHA1 Message Date
Matthew Meszaros aca1aff4d6 feat: count a completed sign-in as a fresh confirmation for the first five minutes of the session, so accounts with no password or second factor can confirm an action by signing in again 2026-10-04 05:13:23 -07:00
Matthew Meszaros db4fc7b115 feat: require a recent confirmation for 2FA enrollment (a fresh sign-in for accounts with no password or factor), pool link approval, workspace export and import, member invites and role changes, webhook and OAuth app secret reveal and rotation, and the admin fleet join token, admin grant and workspace archive routes, with a confirm-it-is-you dialog and retry in the admin panel 2026-10-04 02:56:18 -07:00
Matthew Meszaros 6cadcc725d feat: answer every public request-body bind failure with a 400 that names the problem (empty body, JSON syntax error with its byte offset, wrong JSON type for the body or a named field, missing or out-of-range fields by json key) instead of a blanket malformed-JSON message or a 500, accept a single contact object on POST /v1/contacts as the CLIs send it, and drop the API-key lookup cache whose 300ns TTL made it a Redis round trip that saved nothing 2026-09-22 20:21:41 -07:00
Matthew Meszaros e9d1a7e734 feat: reserve the per-account reauth attempt atomically before checking a password or 2FA code, keep the 2FA dialogs open while a request is in flight, move and trap focus in them, show a retry row when 2FA status fails to load, and drop Idempotency-Key from the recovery-code route with the reason documented 2026-09-19 08:36:59 -07:00
Matthew Meszaros e668a2a36b feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa 2026-09-19 08:18:35 +02:00