towerops/.pre-commit-config.yaml
Graham McIntie 9ecd01dc8f Security hardening: remaining audit fixes
- Encrypt session cookies (add encryption_salt to endpoint)
- X-Frame-Options: SAMEORIGIN → DENY (match CSP frame-ancestors 'none')
- Remove unsafe-eval from CSP script-src
- Apply security headers in all environments (not just prod)
- Add GraphQL query complexity limit (max 500) via Absinthe.Plug
- GraphQL introspection already blocked in prod via plug

Closes audit items #6, #7, #12, #13, #14, #16
2026-02-15 12:54:38 -06:00

Symbolic link
1 line
No EOL
66 B
YAML

/nix/store/4xlkmdd947h5qlhj2rmbyavq08grkz27-pre-commit-config.json