security: harden first preview boundaries
verify / verify (push) Successful in 3m1s

Sanitized snapshot of private source 13a965dd6ea705dd92499f7dbeaa00c25c15247d. Require same-origin evidence for unsafe methods, fail closed on invalid authentication middleware configuration, and bound untrusted request metadata.

AI-Assistance: OpenAI Codex assisted implementation, testing, and security review.
Signed-off-by: Cole Speelman <crspeelman@gmail.com>
This commit is contained in:
2026-08-16 19:20:14 -04:00
parent df946d888e
commit a18f1dd22a
13 changed files with 181 additions and 12 deletions
+3
View File
@@ -192,6 +192,9 @@ func (service *Service) Session(ctx context.Context, token string) (Principal, e
}
func (service *Service) RevokeSession(ctx context.Context, token string) error {
if len(token) < 32 || len(token) > 128 {
return ErrSessionNotFound
}
digest := sha256.Sum256([]byte(token))
return service.repository.DeleteSession(ctx, digest)
}