Log details obfuscated to not leak info

This commit is contained in:
2026-08-26 20:51:29 +02:00
parent b4b40e5c2c
commit 04b8a5a8b9
10 changed files with 109 additions and 22 deletions
+1
View File
@@ -201,6 +201,7 @@
195. Perform a new security audit overwriting Security-audit.md with new and remaining issues.
195. Update SA-012 and README for the implemented refresh-token lifecycle, revocation behavior, and refresh endpoint.
196. Remedy SA-001: migrate logout from JSON token transport to the Authorization bearer header.
197. Implement SA-002: replace raw infrastructure errors with redacted server-side logging, request IDs, and stable public reference messages.
## Future entries