This website requires JavaScript.
Explore
Help
Sign In
starred
/
warmbly
Watch
1
Star
0
Fork
0
mirror of
https://github.com/warmbly/warmbly.git
synced
2026-10-05 16:02:10 +00:00
Code
Issues
Packages
Projects
Releases
Wiki
Activity
Files
35635afeffac221ec77a8fcdb13d30aa63898172
warmbly
/
docs
/
public
T
History
Matthew Meszaros
bf47984cd5
feat: cap every OAuth grant and API key at the delegating member's role (consent narrows scopes and reports the withheld ones, tokens re-check the member's current role at every gate and MCP tool, keys stay within their creator's permissions, mailboxes and IP allowlist), keep OAuth tokens off API key and OAuth app management, require a fresh sign-in to approve an app, revoke a grant whose refresh token is presented twice, count only unexpired grants as installs, seal app webhook secrets under the instance key, name the workspace and flag unverified apps on the consent screen, and let credential managers list and revoke every member's app authorizations
2026-10-04 02:59:10 -07:00
..
_headers
feat: accept only Salesforce domains as an org's API host and call it through the SSRF-guarded client, register the Warmbly Cloud link only on self-hosted instances behind the instance admin with a second factor and dial it through safehttp with fixed error text, keep automation signing secrets in the sealed connection config, answer integration service failures with fixed messages, add security headers to the forms, tracking and docs origins and TLS 1.2+ to the nginx template, compare the captcha bypass in constant time, require TLS 1.2 for IMAP probes, and drop the unused RSA helpers
2026-10-04 02:58:43 -07:00
asyncapi.json
feat: accept realtime API keys and OAuth tokens only in the x-warmbly-token handshake header with the ws ticket alone in the query string, filter token and key params from Phoenix connect logs, refuse realtime keys, OAuth tokens and pool link tokens held by a login-banned user or a suspended app with an uncached key check, and send the key as a header from warmbly events tail
2026-10-04 02:56:18 -07:00
dashboard-campaigns.png
docs: refresh the documentation site, fix inaccurate claims and contact addresses, add SEO primitives (
#90
)
2026-08-05 10:37:27 +02:00
logo.svg
feat: restore site header logo in repo docs
2026-05-31 09:01:42 +02:00
openapi.json
feat: cap every OAuth grant and API key at the delegating member's role (consent narrows scopes and reports the withheld ones, tokens re-check the member's current role at every gate and MCP tool, keys stay within their creator's permissions, mailboxes and IP allowlist), keep OAuth tokens off API key and OAuth app management, require a fresh sign-in to approve an app, revoke a grant whose refresh token is presented twice, count only unexpired grants as installs, seal app webhook secrets under the instance key, name the workspace and flag unverified apps on the consent screen, and let credential managers list and revoke every member's app authorizations
2026-10-04 02:59:10 -07:00