Bind operator mode to a canonical public origin #610

Merged
rockachopa merged 1 commits from timmy/609-canonical-public-origin into main 2026-08-12 01:57:07 +00:00
Member

Closes #609

Requires an explicit canonical HTTPS origin in operator mode, rejects foreign Host values before authentication, derives CSRF and passkey defaults from that trust boundary, and emits HSTS.

TDD: focused 59 passed; full suite 1267 passed.

Closes #609 Requires an explicit canonical HTTPS origin in operator mode, rejects foreign Host values before authentication, derives CSRF and passkey defaults from that trust boundary, and emits HSTS. TDD: focused 59 passed; full suite 1267 passed.
rockachopa added 1 commit 2026-08-12 01:55:12 +00:00
feat: bind operator mode to public origin (Closes #609)
All checks were successful
CI / lint (pull_request) Successful in 1m30s
CI / build-release (pull_request) Successful in 5s
CI / release-candidate (pull_request) Has been skipped
8ea46974ff
rockachopa merged commit 4faf0447be into main 2026-08-12 01:57:07 +00:00
Sign in to join this conversation.
No reviewers
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: stackchain/stackchain-dashboard#610
No description provided.