-
Notifications
You must be signed in to change notification settings - Fork 1
Labels
epicMilestone-level tracking issueMilestone-level tracking issuesecuritySecurity hardeningSecurity hardening
Description
Overview
Add field-level validation and sanitization at all external input boundaries.
Issues
- Gateway webhook payload fields unbounded, enabling prompt injection #868 Gateway webhook payload unbounded fields / prompt injection (medium, S)
- ACP permission cache key null-byte collision vector #872 ACP permission cache key null-byte collision (low, S)
- Config missing upper bound on gateway.max_body_size #875 Config missing upper bound on gateway.max_body_size (low, S)
Internal Critical Path
All independent — parallel.
Cross-Epic Dependencies
| Relation | Epic | Reason |
|---|---|---|
| parallel with | all other epics | isolated to gateway/acp handlers |
No blockers, no dependencies. Fully independent.
Effort: S
Reactions are currently unavailable
Sub-issues
Metadata
Metadata
Assignees
Labels
epicMilestone-level tracking issueMilestone-level tracking issuesecuritySecurity hardeningSecurity hardening