agent-zero/webui/js
Deimos AI 9e3bbb759f fix(security): add Secure flag to CSRF cookie on HTTPS
The CSRF token cookie is set without the Secure flag. On HTTPS
deployments the cookie could be transmitted over plain HTTP if a
mixed-content scenario occurs.

Conditionally add the Secure flag when running on HTTPS
(window.location.protocol === 'https:'). No impact on HTTP-only
deployments.

Severity: Low-Medium
2026-02-26 13:52:04 +00:00
..
AlpineStore.js parse LLM chunk fix, alpine store state save/load 2025-12-02 12:36:42 +01:00
api.js fix(security): add Secure flag to CSRF cookie on HTTPS 2026-02-26 13:52:04 +00:00
components.js Support webui JS/HTML extensions and plugin paths 2026-02-17 10:17:19 +01:00
confirmClick.js refactor settings and scheduler 2026-01-02 14:03:25 +01:00
confirmDialog.js git projects - basic implementation 2026-02-02 23:23:19 -08:00
css.js merge prep 2025-06-30 16:16:51 +02:00
device.js cleanups and fixes 2025-07-12 20:55:53 +02:00
extensions.js Refactor plugin/project helpers; add plugin UI 2026-02-19 17:20:14 +01:00
initFw.js typed messages.js, unified returns from message handlers 2026-02-25 10:28:50 +01:00
initializer.js cleanups and fixes 2025-07-12 20:55:53 +02:00
manifest.json v0.9.5-pre cleanup, polishing, bugfixing 2025-08-25 09:59:44 +02:00
messages.js fix: image attachment 404 on message display 2026-02-25 23:49:44 -08:00
modals.js add extension points coverage; add JS hooks 2026-02-18 12:32:04 +01:00
scroller.js code exec reset polish, history and scroller fix 2026-02-05 16:47:38 +01:00
shortcuts.js project finalizing, openrouter embeddings 2025-11-13 08:52:45 +01:00
sleep.js secrets polishing 2025-08-15 09:35:30 +02:00
speech_browser.js finalize the notification system 2025-07-12 16:36:20 +02:00
sw.js Implement Progressive Web App (PWA) installation support (#688) 2025-08-20 08:27:08 +02:00
time-utils.js timestamp log fix 2026-01-06 19:02:47 +01:00
timeout.js x-components + mcp wip 2025-06-02 09:48:25 +02:00
transformers@3.0.2.js Squashed commit of the following: 2024-12-08 00:27:02 +01:00
websocket.js WebSocket merge 2026-02-01 16:07:45 +01:00