Security fixes + project files: Session fixation, SameSite cookies, audit log redaction, backup integrity, Docker hardening, error sanitization, rate limiting + pre-existing test and UI fixes
Some checks failed
CI / frontend (push) Has been cancelled
CI / docker (push) Has been cancelled
CI / backend (push) Has been cancelled

This commit is contained in:
backup 2026-09-04 00:02:26 -05:00
commit acd95a0891
7 changed files with 874 additions and 16 deletions

View file

@ -79,7 +79,8 @@ func newTestRouter(t *testing.T, db *sql.DB) (*gin.Engine, *file.Service) {
}
t.Cleanup(func() { os.RemoveAll(dir) })
// also ensure backups dir is created by service; we use filepath join
svc, err := file.NewService(filepath.Join(dir, "dynamic"), db)
auditRepo := repositories.NewAuditRepository(db)
svc, err := file.NewService(filepath.Join(dir, "dynamic"), db, auditRepo)
if err != nil {
t.Fatalf("service: %v", err)
}
@ -87,7 +88,7 @@ func newTestRouter(t *testing.T, db *sql.DB) (*gin.Engine, *file.Service) {
sessionRepo := repositories.NewSessionRepository(db)
authMw := middleware.NewAuthMiddleware(sessionRepo, userRepo)
authHandler := NewAuthHandler(userRepo, sessionRepo, "test-secret-32-chars-minimum-length", "", false)
fileHandler := NewFileConfigHandler(svc)
fileHandler := NewFileConfigHandler(svc, auditRepo, userRepo)
r := gin.New()
r.Use(middleware.CORSMiddleware("http://localhost:5173"))