Kühn
|
1c28917bb5
|
Umlaut-Fix: zentrale Transliteration (ae/oe/ue/ss) fuer E-Mails, UPN und sAMAccountName + Release v10
|
2026-09-16 11:27:03 +02:00 |
|
Kühn
|
1ee37c402a
|
OIDC-Integration: Keycloak-Login (Authorization Code Flow + PKCE), app-seitige Rollen bleiben unangetastet
|
2026-09-15 11:41:29 +02:00 |
|
Kühn
|
6ee8582ce5
|
Theme-Toggle: Dark/Light-Mode pro Nutzer (localStorage, System-Default, FOUC-Schutz)
|
2026-09-10 17:34:40 +02:00 |
|
Kühn
|
1aec65dc95
|
Security & UX Release v7
Security:
- H1: Stored-XSS-Fix — Upload-Pfad-Whitelist (Server + Frontend-Guard safeFileUrl)
- H2: Transaktionen repariert — txDb-Contract in db.js (PG + SQLite), Rollback funktioniert
- H3-Vorbereitung: SESSION_SECRET wird in Compose durchgereicht (Fix M3)
- registerLimiter exportiert (Crash-Bug: Route.post ohne Callback)
- LDAP-Sync: PG-Transaktionsabbruch bei UNIQUE-Verstoß behoben (Precheck-Selects)
- LDAP-Filter: nur echte Benutzerkonten (keine Computer/Service-Accounts, Bit 512)
- Rollen app-seitig: Sync ändert nie role/status, neue User immer user+inaktiv
- DB-Cleanup: 82 Computer-/Service-Accounts aus lokaler User-Tabelle entfernt
UX:
- Dashboard: Vorlagen als Table-Liste + Column-Chart (Top 5 in %), 2 gleich große Spalten
- Table-Listen (Dashboard/Vorlageneditor/Aufgaben) scrollbar bis Seitenende
- Pagination 10/Seite im Dashboard, Sidebar-Label Dashboard
|
2026-09-10 16:57:20 +02:00 |
|
Kühn
|
ec2ed91621
|
Rework CSRF: deterministic token from session + self-healing cookie (no more stale 403s)
|
2026-08-31 11:26:00 +02:00 |
|
Kühn
|
03d20b0e09
|
Security fixes N4/H2/H1 + hide template editor for non-admins
|
2026-08-28 10:15:31 +02:00 |
|
Kühn
|
a35721abec
|
Fix file_path: send undefined instead of null
|
2026-08-25 13:24:40 +02:00 |
|
Kühn
|
abb0617356
|
Fix task validation: send boolean for is_checked, omit file_path when null
|
2026-08-25 13:16:28 +02:00 |
|
Kühn
|
dd095d9696
|
Fix CSRF: use getCSRFToken() in getAuthHeaders() to read from cookie
|
2026-08-25 12:17:08 +02:00 |
|
Kühn
|
b0fcabe4a5
|
Fix CSRF token: read from cookie after page reload
|
2026-08-25 12:02:07 +02:00 |
|
Kühn
|
6be1791c62
|
DEV1.0: Initial commit - Workflow Portal with security fixes
- Backend: Express.js + PostgreSQL/SQLite with LDAP/AD integration
- Frontend: React 18 + Vite + TailwindCSS/DaisyUI
- Security fixes applied (2026-07 + 2026-08):
- LDAP injection prevention, CSRF protection, HttpOnly cookies
- Session hashing (SHA-256), account lockout, rate limiting
- Input validation (zod), file upload security, CSP/HSTS headers
- V3: express-rate-limit updated (ip-address SSRF fix)
- V4: postcss updated (nanoid DoS fix)
- V5: Rate-limit on /health endpoint
- V6: Session rotation on login (session fixation prevention)
- V9: Task values array limit (DoS prevention)
- V10: Frontend XSS audit completed
- Docker: Multi-stage build, non-root user, PostgreSQL + backup service
|
2026-08-24 09:45:28 +02:00 |
|