Add state parameter to CLI browser login flow for CSRF protection — CLI generates a random state, frontend passes it through, CLI verifies on callback. Also restrict cli_callback to http: scheme only. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
43 lines
407 B
Text
43 lines
407 B
Text
node_modules
|
|
dist
|
|
*.log
|
|
.DS_Store
|
|
.envrc
|
|
|
|
# build outputs
|
|
.next
|
|
out
|
|
.turbo
|
|
build
|
|
bin
|
|
dist-electron
|
|
*.tsbuildinfo
|
|
|
|
# env
|
|
.env*
|
|
!.env.example
|
|
|
|
# test coverage
|
|
coverage
|
|
|
|
# Go
|
|
server/bin/
|
|
server/tmp/
|
|
server/migrate
|
|
server/daemon
|
|
server/multica
|
|
|
|
# Test artifacts
|
|
test-results/
|
|
apps/web/test-results/
|
|
|
|
# context (agent workspace)
|
|
.context
|
|
|
|
# local settings
|
|
.claude/
|
|
|
|
# platform specific
|
|
*.dmg
|
|
*.app
|
|
server/server
|