- H6: batch interface stats query in get_site_capacity_summary, replacing per-interface SELECT with a single grouped query - H8: explicit expires_at check in MobileAuth and GraphQLAuth plugs as defense in depth — the query already filters expired rows, but a future refactor dropping the filter can't quietly re-enable revoked sessions - H17: Reports LiveView (toggle/delete/run_now) now uses Reports.get_organization_report/2 to scope by organization_id, fixing IDOR where a user could manipulate other tenants' reports by ID - H18: ToweropsWeb.Api.ParamFilter strips identity fields (id, organization_id, user_id, created_by_id, inserted_at, updated_at) from user-supplied API params; applied to devices, sites, checks, and escalation_policies create/update paths to prevent mass-assignment of tenant ownership fields if a changeset cast list ever drifts |
||
|---|---|---|
| .. | ||
| mix/tasks | ||
| snmpkit | ||
| towerops | ||
| towerops_web | ||
| snmp_lib.ex | ||
| snmp_mgr.ex | ||
| snmpkit.ex | ||
| towerops.ex | ||
| towerops_native.ex | ||
| towerops_web.ex | ||