towerops/lib/towerops_web
Graham McIntire fb1d4c564f
security: fix critical vulnerabilities and atom exhaustion risks
Critical fixes:
- Add [:safe] option to binary_to_term to prevent RCE attacks
- Implement whitelist validation for String.to_atom conversions
- Add input validation before String.to_existing_atom usage

Changes:
- MIB compiler and cache: Use safe binary deserialization
- SNMP contexts: Whitelist protocol, device type, and source atoms
- API controllers: Validate error message keys before atom conversion
- Reduce function nesting to comply with Credo standards

All 6,145 tests passing with zero Credo issues.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-02-08 10:30:30 -06:00
..
channels more tests and fixes 2026-02-07 11:50:18 -06:00
components UI improvements 2026-02-05 14:57:11 -06:00
controllers security: fix critical vulnerabilities and atom exhaustion risks 2026-02-08 10:30:30 -06:00
helpers more tests and fixes 2026-02-07 11:50:18 -06:00
live update hammer 2026-02-08 10:08:31 -06:00
plugs update hammer 2026-02-08 10:08:31 -06:00
endpoint.ex fix: improve agent polling and SNMP testing 2026-02-05 12:34:28 -06:00
gettext.ex init 2025-12-21 11:10:43 -06:00
gettext_helpers.ex feat: migrate email templates to gettext (Phase 2 - Emails) 2026-02-02 09:48:30 -06:00
permissions.ex handle mikrotik ssh 2026-02-02 16:42:18 -06:00
plug_exceptions.ex handle exceptions gracefully on api endpoints 2026-02-04 12:18:14 -06:00
router.ex feat: create MonitoringLive base structure with PubSub subscription 2026-02-06 18:27:40 -06:00
telemetry.ex fix: add Oban config to dev.exs and replace Exq telemetry with Oban 2026-01-24 16:39:45 -06:00
user_auth.ex UI improvements 2026-02-05 14:57:11 -06:00