inou/portal
James 5ebf9925ed TASK-018: Fix session management vulnerabilities
- Store session tokens server-side on login (was: generated but not stored)
- Add /api/v1/auth/logout endpoint for server-side session invalidation
- Delete old sessions on login to prevent session fixation attacks
- Add Cache-Control: no-store headers to all auth responses

Security fixes:
1. Session identifiers now rotated on login (old sessions deleted)
2. Logout properly invalidates server-side session
3. Auth responses include anti-caching headers
2026-03-23 00:35:36 -04:00
..
bin Initial commit 2026-02-01 02:43:27 -05:00
lang Document processing pipeline: OpenRouter OCR + Stepfun extraction 2026-03-15 05:28:05 -04:00
static Document processing pipeline: OpenRouter OCR + Stepfun extraction 2026-03-15 05:28:05 -04:00
templates chore: auto-commit uncommitted changes 2026-03-18 20:01:05 -04:00
access_log.go Initial commit 2026-02-01 02:43:27 -05:00
api_client.go Initial commit 2026-02-01 02:43:27 -05:00
api_mobile.go TASK-018: Fix session management vulnerabilities 2026-03-23 00:35:36 -04:00
api_proxy.go Lab reference charts, import tracking, DossierFromEntry consolidation 2026-02-24 05:15:03 -05:00
defense.go Document processing pipeline: OpenRouter OCR + Stepfun extraction 2026-03-15 05:28:05 -04:00
dossier_sections.go Document processing pipeline: OpenRouter OCR + Stepfun extraction 2026-03-15 05:28:05 -04:00
genome.go Document processing pipeline: OpenRouter OCR + Stepfun extraction 2026-03-15 05:28:05 -04:00
import_json.go Lab reference charts, import tracking, DossierFromEntry consolidation 2026-02-24 05:15:03 -05:00
inou-portal Initial commit 2026-02-01 02:43:27 -05:00
main.go Document processing pipeline: OpenRouter OCR + Stepfun extraction 2026-03-15 05:28:05 -04:00
main.go.bak Initial commit 2026-02-01 02:43:27 -05:00
mcp_http.go chore: auto-commit uncommitted changes 2026-03-18 20:01:05 -04:00
mcp_tools.go Checkpoint: all pending changes across lib, portal, api, tools 2026-03-11 23:37:44 -04:00
oauth.go Checkpoint: all pending changes across lib, portal, api, tools 2026-03-11 23:37:44 -04:00
portal Initial commit 2026-02-01 02:43:27 -05:00
trackers.go Lab reference charts, import tracking, DossierFromEntry consolidation 2026-02-24 05:15:03 -05:00
upload.go Document processing pipeline: OpenRouter OCR + Stepfun extraction 2026-03-15 05:28:05 -04:00