9router/src/sse
decolua 0c7c9de00a fix(security): re-auth on DB export/import + SSRF guard on web fetch
- /api/settings/database now requires current password (header for GET,
  body for POST) in addition to session; CLI-token requests exempt
- add verifyDashboardPassword helper reusing login bcrypt check
- profile UI prompts password via modal before export/import
- /v1/web/fetch rejects internal/private/metadata targets via assertPublicUrl

Refs GHSA-qvfm-67h2-2qfx, GHSA-qj3v-64wj-q825

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-13 11:40:35 +07:00
..
handlers fix(security): re-auth on DB export/import + SSRF guard on web fetch 2026-06-13 11:40:35 +07:00
services fix(github): proactively refresh missing/expired Copilot token on models discovery 2026-06-08 10:19:10 +07:00
utils Initial commit 2026-01-05 09:58:59 +07:00