• Joined on 2026-04-11
greggy merged pull request greggy/landingpage-haus-schleusingen#50 2026-05-22 08:33:41 +02:00
Fix #42: CSRF-Schutz für Kontaktformular
greggy closed issue greggy/landingpage-haus-schleusingen#42 2026-05-22 08:33:41 +02:00
Sicherheit: CSRF-Schutz für Kontaktformular
greggy deleted branch feature/issue-43-open-redirect-fix from greggy/landingpage-haus-schleusingen 2026-05-22 08:32:25 +02:00
greggy pushed to main at greggy/landingpage-haus-schleusingen 2026-05-22 08:32:25 +02:00
bd1407f8ab Merge pull request 'Fix #43: Offene Redirects via REQUEST_URI fixen' (#51) from feature/issue-43-open-redirect-fix into main
d44fb337e2 fix(security): replace REQUEST_URI with fixed path in redirects (#43)
Compare 2 commits »
greggy merged pull request greggy/landingpage-haus-schleusingen#51 2026-05-22 08:32:24 +02:00
Fix #43: Offene Redirects via REQUEST_URI fixen
greggy closed issue greggy/landingpage-haus-schleusingen#43 2026-05-22 08:32:24 +02:00
Sicherheit: Offene Redirects via REQUEST_URI fixen
greggy created pull request greggy/landingpage-haus-schleusingen#51 2026-05-22 01:07:47 +02:00
Fix #43: Offene Redirects via REQUEST_URI fixen
greggy created pull request greggy/landingpage-haus-schleusingen#50 2026-05-22 01:07:37 +02:00
Fix #42: CSRF-Schutz für Kontaktformular
greggy created pull request greggy/landingpage-haus-schleusingen#49 2026-05-22 01:07:24 +02:00
Fix #41: CSP und Security Headers implementieren
d44fb337e2 fix(security): replace REQUEST_URI with fixed path in redirects (#43)
a919a392cc fix(security): add CSRF protection to contact form (#42)
greggy created branch feature/issue-41-csp-header in greggy/landingpage-haus-schleusingen 2026-05-22 01:04:59 +02:00
2d9f1838b6 fix(security): add CSP and security headers via .htaccess (#41)
greggy commented on issue greggy/landingpage-haus-schleusingen#43 2026-05-22 01:03:50 +02:00
Sicherheit: Offene Redirects via REQUEST_URI fixen

Phase 1: Analyse abgeschlossen

Komplexität: S (Small)

Spezifikation

Alle 3 Vorkommen von $_SERVER["REQUEST_URI"] in HomeController ersetzen durch festen Pfad:

header("Loca…
greggy commented on issue greggy/landingpage-haus-schleusingen#42 2026-05-22 01:03:41 +02:00
Sicherheit: CSRF-Schutz für Kontaktformular

Phase 1: Analyse abgeschlossen

Komplexität: S (Small)

Spezifikation

CSRF-Token in HomeController implementieren:

  1. Token via bin2hex(random_bytes(32)) generieren und in Session…
greggy commented on issue greggy/landingpage-haus-schleusingen#41 2026-05-22 01:03:31 +02:00
Sicherheit: Content-Security-Policy (CSP) Header implementieren

Phase 1: Analyse abgeschlossen

Komplexität: S (Small)

Spezifikation

CSP-Header via .htaccess setzen:

Content-Security-Policy: default-src 'self'; script-src 'self';…
greggy opened issue greggy/landingpage-haus-schleusingen#48 2026-05-21 14:10:32 +02:00
Aufräumen: Dateien an korrekte Orte im Projekt verschieben
greggy deleted branch feature/issue-46-mvc-refactoring from greggy/landingpage-haus-schleusingen 2026-05-21 14:05:27 +02:00