- H-5: Redact keystroke data from WS message logs — log type/sessionId/bytes only - H-4: Remove private key content/length/passphrase logging, replace with safe single line - H-14: Remove username@hostname from password auth log, use hostId only - M-1: Enforce session ownership in data/resize/disconnect handlers via clientSessions map - C-5: Real host key verification flow — MITM protection blocks changed keys immediately, new hosts ask user via host-key-verify WS message with 30s timeout, pending map resolves on host-key-accept/host-key-reject response - H-13: Shell PROMPT_COMMAND/precmd injection is now opt-in via options.enableCwdTracking Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| prisma | ||
| src | ||
| test | ||
| nest-cli.json | ||
| package-lock.json | ||
| package.json | ||
| seed.js | ||
| tsconfig.build.json | ||
| tsconfig.json | ||