-
-
Notifications
You must be signed in to change notification settings - Fork 0
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
isLoopbackHost misses most of 127.0.0.0/8, so the plaintext exception is narrower than documented
effort:XSExtra smallExtra smallprio:P3Low priorityLow prioritystatus:readyReady to be worked onReady to be worked ontype:bugA defect to fixA defect to fixStatus: Open.#365 In Glyndor/authcore;Supplying an HTTPClient silently disables the redirect guards on every OAuth fetch
effort:SSmallSmallprio:P1High priorityHigh prioritystatus:readyReady to be worked onReady to be worked ontype:bugA defect to fixA defect to fixtype:securitySecurity-relevant changeSecurity-relevant changeStatus: Open.#364 In Glyndor/authcore;Six PHC bound tests are refused by the salt-length check and never reach the bound they name
area:passwordSubsystem: passwordSubsystem: passwordeffort:SSmallSmallprio:P3Low priorityLow prioritystatus:readyReady to be worked onReady to be worked ontype:securitySecurity-relevant changeSecurity-relevant changetype:testTestsTestsStatus: Open.#362 In Glyndor/authcore;The recovery-code fuzz test names an oversized case it does not have, and a test pins the absence of replay protection
effort:SSmallSmallprio:P2Medium priorityMedium prioritystatus:readyReady to be worked onReady to be worked ontype:securitySecurity-relevant changeSecurity-relevant changetype:testTestsTestsStatus: Open.#359 In Glyndor/authcore;The purpose and subject binding tests pass with purpose and subject removed from the HMAC
effort:SSmallSmallprio:P2Medium priorityMedium prioritystatus:readyReady to be worked onReady to be worked ontype:securitySecurity-relevant changeSecurity-relevant changetype:testTestsTestsStatus: Open.#358 In Glyndor/authcore;decodeSecret accepts a TOTP secret of any length, including 40-bit
effort:SSmallSmallprio:P2Medium priorityMedium prioritystatus:readyReady to be worked onReady to be worked ontype:bugA defect to fixA defect to fixtype:securitySecurity-relevant changeSecurity-relevant changeStatus: Open.#357 In Glyndor/authcore;The security audit does not run on pull requests, and has been red for a month
area:metaSubsystem: metaSubsystem: metaeffort:SSmallSmallprio:P1High priorityHigh prioritystatus:readyReady to be worked onReady to be worked ontype:ciCI/CD and automationCI/CD and automationtype:securitySecurity-relevant changeSecurity-relevant changeStatus: Open.#354 In Glyndor/authcore;Two concurrent initialisers both succeed with different keys
area:keymanagerSubsystem: keymanagerSubsystem: keymanagereffort:LLargeLargeprio:P2Medium priorityMedium prioritystatus:readyReady to be worked onReady to be worked ontype:bugA defect to fixA defect to fixtype:securitySecurity-relevant changeSecurity-relevant changeStatus: Open.#350 In Glyndor/authcore;An interrupted key initialisation leaves a directory that cannot restart
area:keymanagerSubsystem: keymanagerSubsystem: keymanagereffort:LLargeLargeprio:P2Medium priorityMedium prioritystatus:readyReady to be worked onReady to be worked ontype:bugA defect to fixA defect to fixStatus: Open.#349 In Glyndor/authcore;New accepts a KeyStore that returns no key material
area:keymanagerSubsystem: keymanagerSubsystem: keymanagereffort:SSmallSmallprio:P2Medium priorityMedium prioritystatus:readyReady to be worked onReady to be worked ontype:bugA defect to fixA defect to fixStatus: Open.#348 In Glyndor/authcore;A control character satisfies the special character rule
area:passwordSubsystem: passwordSubsystem: passwordeffort:SSmallSmallprio:P2Medium priorityMedium prioritystatus:readyReady to be worked onReady to be worked ontype:bugA defect to fixA defect to fixtype:securitySecurity-relevant changeSecurity-relevant changeStatus: Open.#347 In Glyndor/authcore;The secure login recipe tells the reader to hand roll TOTP and reset tokens
effort:SSmallSmallprio:P1High priorityHigh prioritystatus:readyReady to be worked onReady to be worked ontype:docsDocumentationDocumentationStatus: Open.#346 In Glyndor/authcore;