- H12: session and remember-me cookies get http_only + secure (prod-only). Cookie can no longer be read via document.cookie (XSS exfil defense) and the Secure flag is set in production via config/prod.exs. - L2: 404 tracker uses EXPIRE … NX so a sustained probe can't keep refreshing the 60s window and dodge the threshold ban. - L5: vault only reads CLOAK_KEY when :env == :prod — a developer with a prod env var set in their shell won't accidentally encrypt local data with the production key. - L6: health endpoint no longer leaks the app version. - L8: Preseem.dismiss_insight/2 + InsightsLive uses it — dismissing now requires the insight to belong to the user's org (closes IDOR). - L10: SidebarCollapse JS hook stores its click handler and removes it in destroyed(); listeners no longer accumulate across LV navigation. - L11: WebMCP navigate tool rejects anything that isn't a same-origin absolute path (blocks javascript:, data:, off-site URLs).
51 lines
1.7 KiB
Elixir
51 lines
1.7 KiB
Elixir
import Config
|
|
|
|
# Temporarily disable Honeybadger in production
|
|
config :honeybadger,
|
|
exclude_envs: [:prod]
|
|
|
|
# Filter out harmless Oban shutdown messages, repetitive SNMP MIB errors, and noisy health checks
|
|
config :logger, :default_handler,
|
|
filters: [
|
|
drop_oban_shutdown: {
|
|
&Towerops.LoggerFilters.drop_oban_shutdown/2,
|
|
[]
|
|
},
|
|
drop_snmp_mib_errors: {
|
|
&Towerops.LoggerFilters.drop_snmp_mib_errors/2,
|
|
[]
|
|
},
|
|
filter_health_checks: {
|
|
&ToweropsWeb.TelemetryFilter.filter_health_checks/2,
|
|
[]
|
|
}
|
|
]
|
|
|
|
# Do not print debug messages in production
|
|
config :logger,
|
|
level: :info,
|
|
metadata_filter: [oban_shutdown_filter: true]
|
|
|
|
# Configure Swoosh API Client
|
|
config :swoosh, api_client: Swoosh.ApiClient.Req
|
|
|
|
# Disable Swoosh Local Memory Storage
|
|
config :swoosh, local: false
|
|
|
|
# Note we also include the path to a cache manifest
|
|
# containing the digested version of static files. This
|
|
# manifest is generated by the `mix assets.deploy` task,
|
|
# which you should run after static files are built and
|
|
# before starting your production server.
|
|
config :towerops, ToweropsWeb.Endpoint, cache_static_manifest: "priv/static/cache_manifest.json"
|
|
# SSL/TLS is handled by Cloudflared proxy - no force_ssl needed
|
|
|
|
# Coverage rasters live on the shared NFS mount so all replicas can serve
|
|
# them and a pod restart doesn't lose computed predictions. The
|
|
# deployment mounts the NFS share at /data.
|
|
config :towerops, :coverage_storage_dir, "/data/coverage"
|
|
|
|
# Cloudflared terminates TLS in front of the app, so requests reach Phoenix
|
|
# over HTTP — but cookies must still carry the Secure attribute so a
|
|
# downgrade attack or misconfigured route can't leak them over cleartext.
|
|
config :towerops, :secure_cookies, true
|