mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-10 07:57:46 +00:00
1. Fix bootstrap admin demotion: skip set_oidc_user_admin when OIDC_ADMIN_GROUPS is unset so bootstrap/manual admin survives subsequent logins. 2. Login CSRF: bind state to an HttpOnly cookie set at /login and verified with constant-time compare at /callback. 3. JWKS cooldown: throttle refresh to once per 60s to prevent attacker-triggered unbounded IdP fetches via random kid values. 4. Secure cookies: derive secure flag from request scheme when SECURE_COOKIES is not explicitly set; OIDC session defaults to secure on HTTPS connections. 5. Remove dead validation-shaped code: the jwt.decode block with None key that swallowed all exceptions and discarded output. |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| atomic_io.py | ||
| auth.py | ||
| constants.py | ||
| database.py | ||
| exceptions.py | ||
| log_safety.py | ||
| middleware.py | ||
| models.py | ||
| oidc.py | ||
| platform_compat.py | ||
| session_manager.py | ||