Files
proxy/nodejs/routes
wmantly 1026f18c08 Rate-limit host-mutating routes
CodeQL flagged POST/PUT/DELETE /api/host* as missing rate limiting despite
performing authorization -- same authLimiter pattern routes/auth.js already
uses, applied here with a higher ceiling since legitimate admin work (bulk
edits) is expected on these routes.

CodeQL also flagged utils/basicauth.js's SHA-1 hashing as reachable from the
new basicauth-user route -- this is the existing, documented htpasswd-
compatible {SHA} scheme (see the comment on hashPassword), not something
this PR changes; left as-is per that comment's existing "follow-up" note,
since swapping it requires a coordinated change to
ops/nginx_conf/hostfeatures.lua's verification and a migration path for
already-stored hashes.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-15 00:45:24 -04:00
..
2026-07-15 00:45:24 -04:00