Security Audit Fixes: Session fixation prevention, SameSite cookies, audit log redaction, backup integrity, Docker hardening, error sanitization, rate limiting, trusted proxies, and config hardening

This commit is contained in:
backup 2026-09-03 23:55:25 -05:00
commit b587fb87a9
18 changed files with 987 additions and 87 deletions

View file

@ -39,6 +39,11 @@ func (r *SessionRepository) Delete(id string) error {
return err
}
func (r *SessionRepository) DeleteByUserID(userID string) error {
_, err := r.db.Exec(`DELETE FROM sessions WHERE user_id = ?`, userID)
return err
}
func (r *SessionRepository) DeleteExpired() error {
_, err := r.db.Exec(`DELETE FROM sessions WHERE expires_at < ?`, time.Now())
return err