Pulse/internal/api
Pulse Monitor 5b0be4e677 security: fix critical vulnerabilities in auto-registration
- Remove token logging - tokens were being logged in plaintext
- Add client IP logging for security auditing
- Add HTTPS warning when tokens sent over HTTP
- Remove debug output that exposed tokens in console
- Add optional auth requirement via REQUIRE_AUTH_FOR_AUTO_REGISTER env var
- Prevent token exposure in error messages
- Already has duplicate node prevention

Security improvements:
- Tokens no longer logged anywhere
- Source IPs tracked for audit trail
- Optional authentication for high-security environments
- HTTPS enforcement warnings
2025-08-09 10:23:21 +00:00
..
alerts.go Initial clean Go + TypeScript rewrite 2025-07-28 21:24:33 +00:00
config_handlers.go security: fix critical vulnerabilities in auto-registration 2025-08-09 10:23:21 +00:00
diagnostics.go fix: Docker persistence and Windows VM memory reporting 2025-08-06 16:00:22 +00:00
middleware.go feat: Implement security, type safety, and error handling improvements 2025-07-29 17:53:51 +00:00
notifications.go Fix frontend email test field mapping 2025-08-02 18:15:03 +00:00
ratelimit.go feat: add comprehensive security system for API protection 2025-08-06 21:39:52 +00:00
router.go feat: major improvements to cluster detection, auto-registration, and UI 2025-08-08 21:25:28 +00:00
settings.go fix: address additional critical bugs and security vulnerabilities 2025-08-09 10:54:10 +01:00
updates.go fix: complete update system improvements 2025-08-07 11:43:40 +00:00