Audit done. Five read-only review passes covered browser auth and sessions, credentials (passkeys, tokens, OAuth, MCP), authorisation across REST, MCP and UI, cross-project references, and public views and content security. The new help-desk reporter role was included.
No issues found: stored or reflected XSS, cross-project writes, role escalation, and help-desk reporters reaching another reporter's issue.
Fixed, merged in turn:
- https://github.com/badbundle/track-slash-app/pull/184 (eea02fc), account credentials:
- Connector tokens can no longer read or change sign-in methods, email or password, or use site-admin account administration.
- Password changes spend the sign-in budget and end other sessions.
- Two passkey or password-login changes can no longer race each other.
- A passkey registration must belong to the signed-in user.
- Sign-in takes the same time for unknown usernames.
- The MCP user and token tools accept UUID strings; before, no client could call them.
- https://github.com/badbundle/track-slash-app/pull/185 (b0578cf), connectors:
- Tokens → Connected apps lets the user who approved a connector disconnect it, whoever registered it.
- Revoking a connector's token ends its grant.
- Deleting the registrant ends the connector.
- Authorize errors for a client the user has never approved are shown on trackslash's own page.
- The token endpoint budgets failures per client and address together.
- https://github.com/badbundle/track-slash-app/pull/186 (dda1415), requests:
- The sign-in limiter can no longer be exhausted or flooded.
- Password sign-in budgets count failures only, and IPv6 is budgeted by /64.
- JSON, MCP and description sizes are capped.
- Trailing-slash redirects never go off-site.
- Uploads are served sandboxed.
- https://github.com/badbundle/track-slash-app/pull/187 (faccb31), privacy:
- Member search matches emails only for managers, and the UI shows no member emails.
- Block history, deleted issues, their files and their changelog are for members.
- Realtime disconnects when a member is removed or a user deleted.
- Mentions notify only participants.
- Reporters get status notifications in their own terms.
- Saved GitHub tokens follow their owner.
- Admin bootstrap no longer promotes by email without
-promote-existing.
- https://github.com/badbundle/track-slash-app/pull/188 (82ec1e0) adds
SECURITY_MODEL.md: who can see what, the rules every surface follows, and the trade-offs accepted on purpose. These include 403/404 existence probing for private projects, help-desk ref numbering, public member rosters, GitHub metadata on public projects, images kept as uploaded, and no__Host-cookie prefix.