Skip to content

fix: harden A2A, MCP scoped keys, transport limits, auth, and logs - #198

Merged
blisspixel merged 1 commit into
mainfrom
fix/security-hardening-v2.50.24
Oct 9, 2026
Merged

blisspixel merged 1 commit into
mainfrom
fix/security-hardening-v2.50.24

Conversation

@blisspixel

Copy link
Copy Markdown
Owner

Addresses security tracking issues 20 through 27:

  • Issue 20: add A2A connection semaphore, header timeout, and line/byte caps
  • Issue 21: enforce MCP subscription quotas, deduplication, and bounded SSE queue
  • Issue 22: restrict route explanation to expert-scoped key allowlists
  • Issue 23: throttle MCP auth concurrency, use prefix lookup, and coalesce writes
  • Issue 24: restrict dashboard cookie authentication strictly to portraits
  • Issue 25: isolate Lemonade image requests from ambient proxies and redirects
  • Issue 26: defend against regex backtracking, symlink escape, and skill prompt bloat
  • Issue 27: sanitize sensitive tokens from scraping request and redirect logs
  • Release v2.50.24 with updated docs, manifests, checksums, and lockfile

Address security tracking issues 20 through 27:
- Issue 20: add A2A connection semaphore, header timeout, and line/byte caps
- Issue 21: enforce MCP subscription quotas, deduplication, and bounded SSE queue
- Issue 22: restrict route explanation to expert-scoped key allowlists
- Issue 23: throttle MCP auth concurrency, use prefix lookup, and coalesce writes
- Issue 24: restrict dashboard cookie authentication strictly to portraits
- Issue 25: isolate Lemonade image requests from ambient proxies and redirects
- Issue 26: defend against regex backtracking, symlink escape, and skill prompt bloat
- Issue 27: sanitize sensitive tokens from scraping request and redirect logs
- Release v2.50.24 with updated docs, manifests, checksums, and lockfile
@blisspixel
blisspixel merged commit 64edc36 into main Oct 9, 2026
12 checks passed
@blisspixel
blisspixel deleted the fix/security-hardening-v2.50.24 branch October 9, 2026 14:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant