Highlights
Auth Bypass: 1 prior fix. Scrutinize any change in this area.
action.go: most-fixed (1 issue). Treat as high-risk during review.
0 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Auth Bypass: Unauthorized users could access administrative interfaces (such as repository creation) due to a missing site-admin check in the GET request handler. Future features must consistently apply admin-only route guards before rendering action interfaces.
Cleartext Transmission of Sensitive Information: During IndieAuth profile fetching, the client followed redirects to non-HTTPS schemes, potentially exposing sensitive credentials or profile data to Man-in-the-Middle (MitM) attacks.