towerops/lib/towerops_web/controllers
Graham McIntie 34fe5d7e49 Security fixes: mask credentials in logs/API, fix cookie/CSP/LIKE injection/webhooks
CRITICAL fixes:
- Mask SNMP community string in agent channel logs (CRITICAL-1)
- Remove snmpv3 passwords from REST API responses, return _set booleans (CRITICAL-2)
- Replace snmp_community with snmp_community_set in GraphQL type (CRITICAL-3)

HIGH fixes:
- Fix cookie same_site from invalid 'Towerops' to 'Lax' (HIGH-4)
- Remove unsafe-eval from CSP script-src (HIGH-6)
- Block GraphQL introspection queries in production (HIGH-7)
- Sanitize LIKE wildcards in SNMP device name search (HIGH-8)
- Reject webhooks when no secret configured instead of accepting (HIGH-9)

MEDIUM fixes:
- Hash mobile session tokens (SHA-256) before DB storage (MEDIUM-10)
- Apply security headers in all environments, not just prod (MEDIUM-14)
- Add GraphQL query complexity limit (500) in production (MEDIUM-16)
- Fix X-Frame-Options to DENY to match frame-ancestors 'none' (MEDIUM-13)
2026-02-15 09:09:04 -06:00
..
api Security fixes: mask credentials in logs/API, fix cookie/CSP/LIKE injection/webhooks 2026-02-15 09:09:04 -06:00
api_docs_html fix: resolve compilation errors, test failures, and credo issues 2026-02-14 12:23:10 -06:00
error_html i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
graphql_docs_html fix: resolve compilation errors, test failures, and credo issues 2026-02-14 12:23:10 -06:00
page_html marketing: update integration list with all new providers 2026-02-14 21:12:38 -06:00
user_confirmation_html i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
user_registration_html ui: polish auth pages, core components, and visual consistency 2026-02-14 21:11:33 -06:00
user_reset_password_html purge more passkey and gettext updates 2026-02-02 10:20:59 -06:00
user_session_html ui: polish auth pages, core components, and visual consistency 2026-02-14 21:11:33 -06:00
user_settings_html fix: netbox url field type, gaiia ipRange→block, remove unknown webhook log 2026-02-14 17:44:01 -06:00
user_sudo_html fix: netbox url field type, gaiia ipRange→block, remove unknown webhook log 2026-02-14 17:44:01 -06:00
admin_controller.ex Add superuser system with user impersonation for admin support 2026-01-06 12:50:10 -06:00
api_docs_controller.ex updates 2026-01-17 17:49:53 -06:00
api_docs_html.ex updates 2026-01-17 17:49:53 -06:00
debug_controller.ex add headers debug in prod 2026-02-01 10:54:13 -06:00
error_html.ex add error pages 2026-01-06 14:37:48 -06:00
error_json.ex init 2025-12-21 11:10:43 -06:00
graphql_docs_controller.ex feat: add GraphQL API with Absinthe, full schema, resolvers, and documentation 2026-02-14 11:28:57 -06:00
graphql_docs_html.ex feat: add GraphQL API with Absinthe, full schema, resolvers, and documentation 2026-02-14 11:28:57 -06:00
health_controller.ex security fixes 2026-01-28 17:02:36 -06:00
invitation_controller.ex i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
page_controller.ex cookie improvements 2026-01-28 12:30:28 -06:00
page_html.ex init 2025-12-21 11:10:43 -06:00
user_confirmation_controller.ex i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
user_confirmation_html.ex feat: require email verification before first login 2026-02-14 11:28:57 -06:00
user_registration_controller.ex i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
user_registration_html.ex credo cleanup 2026-01-17 15:00:52 -06:00
user_reset_password_controller.ex i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
user_reset_password_html.ex forgot password flow 2026-01-31 17:03:22 -06:00
user_session_controller.ex i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
user_session_html.ex credo cleanup 2026-01-17 15:00:52 -06:00
user_settings_controller.ex i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
user_settings_html.ex credo cleanup 2026-01-17 15:00:52 -06:00
user_sudo_controller.ex i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
user_sudo_html.ex feat: implement sudo mode MFA-only verification controller 2026-02-01 14:34:17 -06:00