Bind operator mode to a canonical public origin #610
No reviewers
Labels
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: stackchain/stackchain-dashboard#610
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "timmy/609-canonical-public-origin"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #609
Requires an explicit canonical HTTPS origin in operator mode, rejects foreign Host values before authentication, derives CSRF and passkey defaults from that trust boundary, and emits HSTS.
TDD: focused 59 passed; full suite 1267 passed.