This website requires JavaScript.
Explore
Help
Sign In
starred
/
warmbly
Watch
1
Star
0
Fork
0
mirror of
https://github.com/warmbly/warmbly.git
synced
2026-10-03 16:02:02 +00:00
Code
Issues
Packages
Projects
Releases
Wiki
Activity
Files
478d3ecc7bfe729e0eaffe56e30bd0c1d6447c3d
warmbly
/
admin
/
public
T
History
Matthew Meszaros
e668a2a36b
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
..
_headers
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
_redirects
feat: let web and admin be served from a static host by teaching each app's own entrypoint to render config.js wherever WARMBLY_CONFIG_OUT points, so one definition of the runtime key set serves both the container that renders it at start and a build:pages script that renders it into dist, ship a _redirects in each so a deep link stops 404ing without nginx try_files, and add scripts/check-pages-build.sh to make lint because a malformed config.js reads fine in a diff and leaves the app blank at runtime
2026-09-10 18:03:00 +02:00
admin-icon.svg
feat: optically center the Warmbly mark in the admin favicon
2026-06-01 16:19:29 +02:00
apple-touch-icon.png
feat: add a complete admin favicon set (ico, png, apple-touch, manifest)
2026-06-01 16:43:27 +02:00
config.js
feat: add the same runtime config shim to the admin panel so its built image reads api url, dashboard url, env label, and turnstile key from container env
2026-07-22 18:40:06 +02:00
favicon-16x16.png
feat: add a complete admin favicon set (ico, png, apple-touch, manifest)
2026-06-01 16:43:27 +02:00
favicon-32x32.png
feat: add a complete admin favicon set (ico, png, apple-touch, manifest)
2026-06-01 16:43:27 +02:00
favicon.ico
feat: add a complete admin favicon set (ico, png, apple-touch, manifest)
2026-06-01 16:43:27 +02:00
icon-192.png
feat: add a complete admin favicon set (ico, png, apple-touch, manifest)
2026-06-01 16:43:27 +02:00
icon-512.png
feat: add a complete admin favicon set (ico, png, apple-touch, manifest)
2026-06-01 16:43:27 +02:00
site.webmanifest
feat: add a complete admin favicon set (ico, png, apple-touch, manifest)
2026-06-01 16:43:27 +02:00