mirror of
https://github.com/Routstr/routstr-core.git
synced 2026-10-06 12:38:23 +00:00
Address review hardening items on the secret-storage path: - vault.verify_password caps N/r/p at the parameters this module emits, so a tampered or corrupt stored hash can't force an unbounded scrypt work factor (memory grows with N*r) and turn a login into an OOM/DoS. - bootstrap prints the generated first-run admin password to stdout instead of the logger, so it reaches the operator once without being persisted into the on-disk log files. - admin_login reads the password hash while the DB session is open rather than off a detached ORM instance after the context exits. - drop a stray debug print of the request payload in upsert_provider_model. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>