towerops/lib/towerops_web/plugs
Graham McIntire 8682cdce55 fix: resolve session salts at runtime so prod release boots
The @session_options module attribute used Application.compile_env, which
baked compile-time placeholders into the endpoint while runtime.exs set
the real values from SESSION_SIGNING_SALT / SESSION_ENCRYPTION_SALT env
vars. Phoenix detected the mismatch and refused to start (failing migrate
Job in k8s).

- Remove hardcoded salts from config/config.exs (no compile-time binding)
- Add stable per-env salts in dev.exs / test.exs so local + CI don't need
  the env vars
- Split static cookie opts (@static_session_options) from runtime-resolved
  opts in endpoint.ex; expose session_options/0 as an MFA tuple in socket
  connect_info so LiveView decodes sessions with the same runtime salts
- New ToweropsWeb.Plugs.RuntimeSession wraps Plug.Session, fetches salts
  from app env on first request, and caches the initialized opts in
  :persistent_term (zero per-request overhead after warm-up)
2026-05-12 16:26:54 -05:00
..
api_auth.ex refactor: use API token auth for profile imports instead of session cookies 2026-01-18 09:30:21 -06:00
brute_force_protection.ex fix: 11 critical security/correctness bugs from code audit 2026-05-12 10:20:52 -05:00
capture_timezone.ex Use detected timezone from session in user registration 2026-02-01 12:18:33 -06:00
check_policy_consent.ex gdpr consent tracking 2026-01-29 11:12:35 -06:00
detect_eu_user.ex fix: remaining bugs.md findings — Repo calls, process dict, CSS, rate limits, Oban, debug route 2026-05-11 19:34:18 -05:00
filter_noisy_logs.ex fix: properly disable Plug.Telemetry logging for health checks 2026-03-08 16:39:26 -05:00
graphql_auth.ex fix: 5 more high-severity bugs (H6, H8, H17, H18) 2026-05-12 11:04:31 -05:00
graphql_introspection.ex Security fixes: mask credentials in logs/API, fix cookie/CSP/LIKE injection/webhooks 2026-02-15 09:09:04 -06:00
markdown_negotiation.ex fix: correct login URL path in markdown negotiation content 2026-04-17 15:50:31 -05:00
mobile_auth.ex fix: 5 more high-severity bugs (H6, H8, H17, H18) 2026-05-12 11:04:31 -05:00
rate_limit.ex fix: remaining bugs.md findings — Repo calls, process dict, CSS, rate limits, Oban, debug route 2026-05-11 19:34:18 -05:00
remote_ip_logger.ex perf: disable Req retry for faster error tests 2026-03-10 16:19:31 -05:00
runtime_session.ex fix: resolve session salts at runtime so prod release boots 2026-05-12 16:26:54 -05:00
security_headers.ex fix: API token access control, admin form crash, MIB validation, CSP dedup 2026-05-12 09:08:57 -05:00
update_session_activity.ex perf+refactor: codebase-wide query and antipattern audit 2026-04-28 16:58:51 -05:00
webhook_auth.ex fix: 6 medium-severity bugs (M2, M8, M9, M10, M11, M16) 2026-05-12 11:38:13 -05:00