hotyue
|
50cf3f21e6
|
security: 6-item hardening pass (OTA auth, SQLi, HMAC, SSRF, supply chain, env) (#109)
- #106 Master OTA Telegram callback requires TG_MASTER_TOKEN authentication
- #105 toggle command uses whitelist validation instead of raw SQL concat
- #108 HMAC signature covers all query params (path + sorted params) on both sides
- #107 Remove curl -k, add internal domain SSRF interception (.local/.internal/.nip.io)
- Supply chain: IPS-MAGIC integrity verification for all 6 install modules
- Env: confirmed config.conf/master.conf chmod 600, no .env leak risk
9 files changed, +120/-13 lines
Co-authored-by: hotyue <hotyue@users.noreply.github.com>
|
2026-08-10 12:22:05 +08:00 |
|