Skip to content

Harden API, desktop, and Drive trust boundaries - #9

Merged
ishu86 merged 51 commits into
mainfrom
harden/audit
Sep 5, 2026
Merged

ishu86 merged 51 commits into
mainfrom
harden/audit

Conversation

@ishu86

@ishu86 ishu86 commented Sep 5, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Close the Host/Origin, live-view, and credential-injection gaps: desktops sit on case-desks and relay through cased, login rechecks the live page (HTTPS except loopback), deskd gates exec/files during injection, and uploads are capped at 8 MiB as the body arrives.
  • Lock down vault and phone handoffs: private vault perms, SQLite reads hold the connection lock, ntfy Approve/Deny only on signed HTTPS URLs when CASE_PUBLIC_HOST is set, and CI Actions are pinned to commits.
  • Refresh SECURITY.md, README, and CONTRIBUTING to match the enforced model. Working notes stay out of the tree (docs/ is gitignored). Existing desktop containers still need recreation to join case-desks.

Made with Cursor

…ealthcheck.

Follow-up: pip --require-hashes would need a full lock file for the deskd venv,
so the pins here are versions only.
…daily schedules on wall-clock time across DST.
ishu86 and others added 21 commits September 4, 2026 05:13
Co-authored-by: Cursor <cursoragent@cursor.com>
@ishu86
ishu86 merged commit 18d520b into main Sep 5, 2026
3 checks passed
@ishu86
ishu86 deleted the harden/audit branch September 5, 2026 06:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant