Join Nostr
2026-09-15 17:00:24 UTC

npub10l…sv2ux on Nostr: [ steve02081504/fount ] security: clean up code-scanning alerts (#337) * security: ...

[ steve02081504/fount ] security: clean up code-scanning alerts (#337)

* security: address code-scanning alerts

- Replace Math.random with crypto in service generators / session / svg inliner / userscript
- Escape toast text and notification i18n attrs; keep sanctioned HTML toast channel
- Validate redirect/hostnames (login, tutorial, deskpet, char-download, badges)
- Clamp backend-driven toast duration; secure cookie on https
- Restrict workflow token permissions; harden regexp escapes
- Add toast frontend regression tests (plain text escaped, custom HTML kept)
https://github.com/steve02081504/fount/commit/045f7ed822b2753e8882296a14028c5d6f363e32