v1.0.3 - Security hardening
Patch / security bug-fix release. Close gaps found in the 2026-07 audit: forgeable session signing key (placeholder passes prod validation), voip.ms credential leakage into logs/DB, channel secrets readable via the API, webhook SSRF via DNS, third-party CDN scripts without SRI, public-page privacy leaks, and minor API hardening (OIDC nonce, POST logout, media path validation). Behaviour-preserving where possible. Audit findings F-06, F-07, F-08, F-12, F-20, F-21, F-31.
No due date
100% Completed