summaryrefslogtreecommitdiffstats
path: root/pyproject.toml
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-01 20:05:39 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-01 20:05:39 +0200
commita9eb121476eb8128e0cf1ae280ed0fea84d4b2aa (patch)
tree3edead9b59d9958fda956a58d075a25ea9f6d270 /pyproject.toml
parentf2915bc7b1550b80cadfa36f5910223106cb3bfe (diff)
downloadmeshbay-a9eb121476eb8128e0cf1ae280ed0fea84d4b2aa.tar.gz
docs: mark M4 and M5 fixed in the third security review
M4: federation `source_hub` bound to the token signer, push capped, revocation prunes the peer's own directory entries, state-changing MHP tokens are single-use. M5: a middleware adds a CSP and the other protective headers to every response, matching the desktop client's policy for these files. Every finding in the review (H1, H2, M1-M6) is now fixed; the summary, findings table and action plan reflect that. Original finding texts kept for the record. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011pG75yGK3NthNfyjH74omG
Diffstat (limited to 'pyproject.toml')
0 files changed, 0 insertions, 0 deletions