719afa8533ce3a1e62ba21679e09b67649fbfcb6
- XSS: escape serviceName in waking page HTML - Session TTL: 24h expiration with periodic cleanup - Rate limit: 5 login attempts / 15 min per IP - CORS: restrict to same-origin + localhost - SSRF: block localhost/metadata in service targets - UpSnap: log response bodies on auth/wake failures Co-Authored-By: Claude <noreply@anthropic.com>
Description
No description provided
Languages
TypeScript
62.4%
Svelte
32%
Dockerfile
3.3%
CSS
1.4%
JavaScript
0.5%
Other
0.4%