Skip to content

merge security fix from upstream#2

Merged
aeltorio merged 2 commits into
sctg-development:cors-allow-hostfrom
icebear0828:dev
May 26, 2026
Merged

merge security fix from upstream#2
aeltorio merged 2 commits into
sctg-development:cors-allow-hostfrom
icebear0828:dev

Conversation

@aeltorio
Copy link
Copy Markdown

No description provided.

icebear0828 and others added 2 commits May 25, 2026 04:00
- Move proxy_api_key check before active===0 early-return in chat route (auth bypass)
- Use constant-time comparison for API key validation (timing side-channel)
- Parse Bearer prefix with case-insensitive regex (RFC 7235 compliance)
- Cap compact handler retries at 8 (prevent infinite loop)
- Add _destroyed flag to RefreshScheduler semaphore (prevent negative count after destroy)
fix(security): patch critical/high defects from code audit
@aeltorio aeltorio merged commit 720d7e1 into sctg-development:cors-allow-host May 26, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants