This website requires JavaScript.
Explore
Help
Sign In
starred
/
warmbly
Watch
1
Star
0
Fork
0
mirror of
https://github.com/warmbly/warmbly.git
synced
2026-10-06 08:02:06 +00:00
Code
Issues
Packages
Projects
Releases
Wiki
Activity
Files
fd940d905b9e90cd2acd5ceea60967be246c656d
warmbly
/
docs
/
public
T
History
Matthew Meszaros
663c3013d1
feat: bind each Remie approval to its tool call and run it once, show every argument and the resolved send on dashboard and Slack approval cards, keep always-allow to settings managers with a revocable list and never for tools that start sending or change access, withhold secrets and unpermitted tool results from the assistant and shared conversations, gate /mcp, /ai/tools and the web and playbook tools on AI_AGENT or use_ai, and scope get_mailbox by organization
2026-10-04 03:45:02 -07:00
..
_headers
feat: accept only Salesforce domains as an org's API host and call it through the SSRF-guarded client, register the Warmbly Cloud link only on self-hosted instances behind the instance admin with a second factor and dial it through safehttp with fixed error text, keep automation signing secrets in the sealed connection config, answer integration service failures with fixed messages, add security headers to the forms, tracking and docs origins and TLS 1.2+ to the nginx template, compare the captcha bypass in constant time, require TLS 1.2 for IMAP probes, and drop the unused RSA helpers
2026-10-04 02:58:43 -07:00
asyncapi.json
feat: accept realtime API keys and OAuth tokens only in the x-warmbly-token handshake header with the ws ticket alone in the query string, filter token and key params from Phoenix connect logs, refuse realtime keys, OAuth tokens and pool link tokens held by a login-banned user or a suspended app with an uncached key check, and send the key as a header from warmbly events tail
2026-10-04 02:56:18 -07:00
dashboard-campaigns.png
docs: refresh the documentation site, fix inaccurate claims and contact addresses, add SEO primitives (
#90
)
2026-08-05 10:37:27 +02:00
logo.svg
feat: restore site header logo in repo docs
2026-05-31 09:01:42 +02:00
openapi.json
feat: bind each Remie approval to its tool call and run it once, show every argument and the resolved send on dashboard and Slack approval cards, keep always-allow to settings managers with a revocable list and never for tools that start sending or change access, withhold secrets and unpermitted tool results from the assistant and shared conversations, gate /mcp, /ai/tools and the web and playbook tools on AI_AGENT or use_ai, and scope get_mailbox by organization
2026-10-04 03:45:02 -07:00