Skip to content

[Security] Harden the MVP before enabling Funnel #29

Description

@troyscott

Outcome

Complete an evidence-backed security review before the public URL is enabled.

Acceptance criteria

  • Public process has read-only filesystem permissions.
  • Host, CSRF, cookie, CSP, and Markdown-sanitization controls are tested.
  • Source fetching passes allowlist and redirect tests.
  • Secrets and private reader data are absent from public responses and Git history.
  • Funnel is enabled only after the release checklist passes.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: deploymentMac mini and Tailscale deploymentmvpRequired for the first usable releasepriority: criticalBlocks safe deployment or releasesecuritySecurity boundary or hardening work

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions