Files
cgalo5758 b245bdb0a9 Fix security audit findings from 2026-09-21 scan
Remediate six confirmed security issues: deployment-only config keys,
bounded provider responses, short-lived registration sessions, private
init file mode, FedWiki workflow authorization, and switch preview
gates.

- Add DeploymentOnly config key declaration; refuse runtime overrides
  for keys that decide where secrets are sent
- Create httplimit package; bound all provider response reads at 8 MiB
- Set fifteen-minute deadline on /register sessions
- Write mc-config.yaml with 0600 permissions
- Derive FedWiki workflow IDs from site IDs; re-authorize sites before
  mutating activities
- Apply switch authorization gates to the proration preview
2026-09-21 13:57:57 -05:00

421 B

Codex Security scan

Run a Codex Security scan of the repository in your working directory: the security-scan skill, one standard pass, headless. The repository is a disposable copy; read anything, run anything. Its SECURITY.md is the inherited security policy. Scanner output for the whole repository is in /out/tools/ as leads. Finish when the scan directory holds report.md, then print the report's summary.