| .. |
|
config
|
fix(logging): gate CF-Connecting-IP on a Cloudflare peer, not any trusted proxy
|
2026-07-26 10:23:04 -05:00 |
|
db
|
Merge pull request #254 from ChrisChrome/main
|
2026-08-11 15:45:39 -05:00 |
|
lib
|
Customer Entra tenants: verify the domain, then be believed
|
2026-08-11 23:05:25 -05:00 |
|
middleware
|
Merge branch 'fix/recovery-grants' into release/auth-campaign
|
2026-07-26 16:22:59 -05:00 |
|
player
|
Add org-level widget sandbox isolation toggle with warnings
|
2026-08-10 21:14:42 +00:00 |
|
routes
|
Link start cannot be navigated to: a bearer token does not survive it
|
2026-08-12 14:44:23 -05:00 |
|
scripts
|
fix(content+android): rotation-aware media — portrait upright on dashboard AND player (#170) (#172)
|
2026-07-12 22:05:11 -05:00 |
|
services
|
#240: stop the morning wave buying itself a blocking checkpoint
|
2026-08-06 20:22:21 -05:00 |
|
test
|
Link start cannot be navigated to: a bearer token does not survive it
|
2026-08-12 14:44:23 -05:00 |
|
ws
|
Add org-level widget sandbox isolation toggle with warnings
|
2026-08-10 21:14:42 +00:00 |
|
.gitignore
|
feat(email): Microsoft Graph send + alert spam protection + preferences UI
|
2026-05-12 18:16:40 -05:00 |
|
config.js
|
SSO: prove domain ownership by DNS, and fix what the second review found
|
2026-08-10 19:23:46 -05:00 |
|
package-lock.json
|
chore(release): v1.9.34-alpha5
|
2026-08-12 14:49:13 -05:00 |
|
package.json
|
chore(release): v1.9.34-alpha5
|
2026-08-12 14:49:13 -05:00 |
|
server.js
|
Close the third QA round: limiter bypass, stored XSS, break-glass, org placement
|
2026-08-11 11:25:11 -05:00 |
|
smoke-ui.js
|
Keep the smoke test out of npm test, and update the lockfile
|
2026-07-28 20:34:34 -05:00 |
|
version.js
|
chore(version): single-source VERSION, env-configurable data paths, bump tooling
|
2026-06-10 12:56:03 -05:00 |