Skip to content

fix: enhance security validations, complete English translations, and fix punctuation - #270

Closed
agostino-code wants to merge 1 commit into
router-for-me:mainfrom
agostino-code:fix/security-i18n-improvements
Closed

agostino-code wants to merge 1 commit into
router-for-me:mainfrom
agostino-code:fix/security-i18n-improvements

Conversation

@agostino-code

Copy link
Copy Markdown

Summary of Changes

1. Security Enhancements

  • Path Traversal & Control Character Validation:
    • src-tauri/src/management_api.rs: Enforced strict checks on path parameters and file names against directory traversal sequences (..), null bytes, and control characters.
    • src-tauri/src/oauth_browser.rs & src-tauri/src/core_config/aliases.rs: Added URI scheme and control character validation for browser launch and external URL opening.
  • Upload File Size Limiting:
    • Enforced a 10 MB payload limit for auth credential files on both backend (management_api.rs) and client-side (managementApi.ts).
  • Dev Server Loopback Binding:
    • package.json: Updated Vite dev command to bind strictly to 127.0.0.1 instead of

@agostino-code
agostino-code force-pushed the fix/security-i18n-improvements branch from 0a274f2 to 960c0b0 Compare September 21, 2026 17:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant