fix(security): audit batch A — validation, rate limiting, sessions #20
Reference in New Issue
Block a user
Delete Branch "fix/audit-critical-backend"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Audit remediation batch A (AUDIT_REPORT.md H-1/H-2/M-1/M-4/M-6/L-3): FluentValidation auto-validation, rate limiting (global+auth+expensive), absolute session lifetime, no default DB password (fail-fast), EmailLabel tenant filter, SMTP log level. 6 new tests; 48/48 green. Includes the audit report itself.
🤖 Generated with Claude Code