- /api/settings/database now requires current password (header for GET, body for POST) in addition to session; CLI-token requests exempt - add verifyDashboardPassword helper reusing login bcrypt check - profile UI prompts password via modal before export/import - /v1/web/fetch rejects internal/private/metadata targets via assertPublicUrl Refs GHSA-qvfm-67h2-2qfx, GHSA-qj3v-64wj-q825 Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|---|---|---|
| .. | ||
| auth | ||
| db | ||
| mcp | ||
| network | ||
| oauth | ||
| qoder | ||
| tunnel | ||
| updater | ||
| usage | ||
| appUpdater.js | ||
| consoleLogBuffer.js | ||
| dataDir.js | ||
| disabledModelsDb.js | ||
| localDb.js | ||
| mitmAliasCache.js | ||
| providerNormalization.js | ||
| requestDetailsDb.js | ||
| usageDb.js | ||