- New in-memory login throttle (handler/login_throttle.go): 5 failed
attempts per IP or per username within 5 minutes locks that key out for
5 minutes, applied to both /login and the TOTP verification step, which
previously had no rate limiting at all
- router.New now adds middleware.Secure with X-Frame-Options,
X-Content-Type-Options, Referrer-Policy, and HSTS (only when cookies
are Secure, implying an HTTPS deployment). No CSP: the existing
templates rely on inline <script> blocks, so a CSP strict enough to
matter would need 'unsafe-inline' anyway
- All session/auth cookies now set Secure based on the new
--cookie-secure flag / WGUI_COOKIE_SECURE env var (default true) so the
session cookie is never sent over plain HTTP unless explicitly opted
into an HTTP-only LAN deployment
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ATVUwTa4Pqwq26orW5BcDW