fix(review-2): medium/low + docs — config validation, hygiene, doc sync
- compression_concurrency wired to boot config (state.rs) and removed as a dead admin control. - patch_config gains per-key integer/range validation so numerically-valid-but- nonsensical values (-1/NaN/3.5) are rejected instead of silently reverting to default at read time. - clearAuth now also clears the display name (shared-device residual). - e2e/Caddyfile.test mirrors prod security headers + the SSE encode-exclusion so the test stack is representative and can catch header regressions. - .gitignore: ignore root-level Playwright artifacts (test-results/, report). - docs: USER_JOURNEYS §10 and SECURITY-BACKLOG updated to match the implemented read-only-ban behavior and the export-path fix. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -64,8 +64,11 @@ decompression-bomb cap (`image::Limits` 12000×12000 / 256 MiB) lives in
|
||||
(not just the exact dev sentinel) and enforces `len ≥ 32` unconditionally in prod.
|
||||
- **Unspoofable client IP in the rate limiter** — `client_ip` now takes the right-most
|
||||
`X-Forwarded-For` entry (the hop Caddy appends), so a client-supplied left-most value is ignored.
|
||||
- **Live role/ban re-check** — the auth extractor re-reads the user row and trusts the DB role and
|
||||
`is_banned` flag rather than the JWT claim, revoking demoted/banned sessions immediately.
|
||||
- **Live role/ban re-check** — the auth extractor re-reads the user row and trusts the DB `role`
|
||||
and `is_banned` flag rather than the JWT claim, so a demote/ban takes effect immediately (no
|
||||
30-day token window). Bans are enforced on write handlers + the host/admin extractors, preserving
|
||||
the documented read-only access for banned guests (USER_JOURNEYS §10); demoted hosts lose host
|
||||
powers at once.
|
||||
- **Container healthchecks** — `app` and `frontend` now have healthchecks and Caddy waits on
|
||||
`service_healthy`.
|
||||
- **Event-scoped `ban_user`** — the ban UPDATE is now scoped by `event_id` like its siblings.
|
||||
|
||||
Reference in New Issue
Block a user