
curo1305andClaude Sonnet 4.6
8629bc0854
docs(phase-7): add security threat verification — 12/12 CLOSED
Formal Phase 7 SECURITY.md:
- T-07-01: api_key_enc excluded from GET /api/admin/ai-config (whitelist)
- T-07-02: HKDF domain separation confirmed (ai-provider-settings vs cloud-credentials)
- T-07-03: is_active atomic UPDATE, no read-then-write
- T-07-04: empty api_key normalised to "not-needed" before AsyncOpenAI
- T-07-05/07/09/11: accepted risks documented
- T-07-06/08/10/12: mitigations verified in implementation + tests
bandit: zero HIGH; npm audit: zero high/critical; threats_open: 0
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-05 10:50:44 +02:00
..
2026-06-02 15:32:06 +02:00
2026-05-30 11:57:54 +02:00
2026-06-05 10:50:44 +02:00
2026-05-21 20:42:16 +02:00
2026-06-02 16:10:59 +02:00
2026-06-03 18:34:49 +02:00
2026-05-21 18:58:15 +02:00
2026-05-29 07:34:22 +02:00
2026-06-05 10:44:24 +02:00
2026-06-05 10:44:24 +02:00
2026-06-02 16:10:59 +02:00