mirror of
https://github.com/RedWizardsLab/EchoHub.git
synced 2026-09-04 00:26:07 +02:00
Refactor and update various components of EchoHub.Server
- Updated launchSettings.json for consistency. - Refactored FileValidationHelper to improve image validation logic. - Enhanced ServerDirectoryService for better connection handling and user count updates. - Improved DatabaseSetup for legacy database handling and seeding default channels. - Refined FirstRunSetup to ensure JWT secret generation. - Removed appsettings.Development.json as it is no longer needed. - Updated EchoHub.Tests project file for consistency. - Added unit tests for FileValidationHelper and PresenceTracker with improved assertions. - Updated ValidationConstantsTests to ensure regex validations are correct. - Cleaned up solution file formatting for better readability.
This commit is contained in:
+24
-24
@@ -1,24 +1,24 @@
|
||||
# Security Policy
|
||||
|
||||
## Reporting a vulnerability
|
||||
|
||||
If you believe you’ve found a security vulnerability in EchoHub (for example: auth bypass, token leakage, file upload validation bypass, RCE, etc.), please **do not** open a public GitHub issue.
|
||||
|
||||
Preferred: use GitHub’s private vulnerability reporting ("Report a vulnerability"):
|
||||
|
||||
- https://github.com/HueByte/EchoHub/security/advisories/new
|
||||
|
||||
If that link is unavailable for your account, contact the maintainer via GitHub:
|
||||
|
||||
- https://github.com/HueByte
|
||||
|
||||
## What to include
|
||||
|
||||
- A clear description of the issue and potential impact
|
||||
- Reproduction steps or a proof-of-concept
|
||||
- Affected versions / commit SHA
|
||||
- Any relevant logs (with secrets removed)
|
||||
|
||||
## Disclosure
|
||||
|
||||
I’ll acknowledge receipt, investigate, and work on a fix. Please avoid publicly disclosing details until a fix is available.
|
||||
# Security Policy
|
||||
|
||||
## Reporting a vulnerability
|
||||
|
||||
If you believe you’ve found a security vulnerability in EchoHub (for example: auth bypass, token leakage, file upload validation bypass, RCE, etc.), please **do not** open a public GitHub issue.
|
||||
|
||||
Preferred: use GitHub’s private vulnerability reporting ("Report a vulnerability"):
|
||||
|
||||
- https://github.com/HueByte/EchoHub/security/advisories/new
|
||||
|
||||
If that link is unavailable for your account, contact the maintainer via GitHub:
|
||||
|
||||
- https://github.com/HueByte
|
||||
|
||||
## What to include
|
||||
|
||||
- A clear description of the issue and potential impact
|
||||
- Reproduction steps or a proof-of-concept
|
||||
- Affected versions / commit SHA
|
||||
- Any relevant logs (with secrets removed)
|
||||
|
||||
## Disclosure
|
||||
|
||||
I’ll acknowledge receipt, investigate, and work on a fix. Please avoid publicly disclosing details until a fix is available.
|
||||
|
||||
Reference in New Issue
Block a user