towerops/lib/towerops_web/plugs
Graham McIntire 8338d0af1e fix: remaining bugs.md findings — Repo calls, process dict, CSS, rate limits, Oban, debug route
- Extract Repo calls from LiveViews into Agents.get_agent_token_for_org/2
  and Accounts.verify_new_totp_device/2 context functions
- Remove Process dictionary usage for cookie consent; use explicit assigns
- Reject url() references in status page custom CSS changeset
- Add per-organization rate limit check alongside per-IP
- Document Oban flush as emergency-only with audit logging
- Gate /admin/headers behind dev_routes (debug endpoint)
2026-05-11 19:34:18 -05:00
..
api_auth.ex refactor: use API token auth for profile imports instead of session cookies 2026-01-18 09:30:21 -06:00
brute_force_protection.ex test: improve test coverage and code quality 2026-03-15 14:49:55 -05:00
capture_timezone.ex Use detected timezone from session in user registration 2026-02-01 12:18:33 -06:00
check_policy_consent.ex gdpr consent tracking 2026-01-29 11:12:35 -06:00
detect_eu_user.ex fix: remaining bugs.md findings — Repo calls, process dict, CSS, rate limits, Oban, debug route 2026-05-11 19:34:18 -05:00
filter_noisy_logs.ex fix: properly disable Plug.Telemetry logging for health checks 2026-03-08 16:39:26 -05:00
graphql_auth.ex perf+refactor: codebase-wide query and antipattern audit 2026-04-28 16:58:51 -05:00
graphql_introspection.ex Security fixes: mask credentials in logs/API, fix cookie/CSP/LIKE injection/webhooks 2026-02-15 09:09:04 -06:00
markdown_negotiation.ex fix: correct login URL path in markdown negotiation content 2026-04-17 15:50:31 -05:00
mobile_auth.ex perf+refactor: codebase-wide query and antipattern audit 2026-04-28 16:58:51 -05:00
rate_limit.ex fix: remaining bugs.md findings — Repo calls, process dict, CSS, rate limits, Oban, debug route 2026-05-11 19:34:18 -05:00
remote_ip_logger.ex perf: disable Req retry for faster error tests 2026-03-10 16:19:31 -05:00
security_headers.ex fix: vendor Leaflet 1.9.4 locally instead of fetching from unpkg 2026-05-01 17:06:54 -05:00
update_session_activity.ex perf+refactor: codebase-wide query and antipattern audit 2026-04-28 16:58:51 -05:00
webhook_auth.ex fix: address security and reliability findings from bugs.md review 2026-05-11 18:54:12 -05:00