Files
T
cgalo5758 0b28a9dc29 Remediate security audit findings
- Replace gorilla/csrf with net/http CrossOriginProtection
- Require valkey-password and add TLS options for session store
- End session at /logout and revoke refresh tokens
- Re-derive identity and roles from provider every five minutes
- Process each Stripe webhook event in its own Temporal workflow
- Give each outbox entry its own workflow with Temporal retries
- Guard against stale Stripe events with provider timestamps
- Derive transport security from base-url scheme
2026-09-09 13:25:43 -05:00

42 lines
1.3 KiB
HTML

{{- /* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-Commercial */ -}}
{{- /* SPDX-FileCopyrightText: 2025-2026 Christian Galo */ -}}
<!DOCTYPE html>
<html lang="en">
<head>
<title>{{ .Header.Title }} - {{ deploymentName }}</title>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<link href="/static/bootstrap.css" rel="stylesheet">
<link rel="apple-touch-icon" sizes="180x180" href="/static/apple-touch-icon.png">
<link rel="icon" type="image/png" sizes="32x32" href="/static/favicon-32x32.png">
<link rel="icon" type="image/png" sizes="16x16" href="/static/favicon-16x16.png">
<link href="/static/app.css" rel="stylesheet">
</head>
<body class="d-flex flex-column vh-100">
<nav class="navbar navbar-dark bg-dark">
<div class="container-fluid">
<a class="navbar-brand" href="/">{{ deploymentName }}</a>
</div>
</nav>
<!-- The one page without a shell (no session is required to see it); it
still titles itself through the page-anatomy part. -->
<main class="flex-grow-1 p-4">
<div class="container">
<div class="col-lg-8 col-xl-6 mx-auto">
{{ template "pageHeader" .Header }}
<a class="btn btn-primary mt-2" href="{{ .Action.Href }}">{{ .Action.Label }}</a>
</div>
</div>
</main>
</body>
</html>