mirror of
https://github.com/tiennm99/goclaw.git
synced 2026-06-10 00:13:42 +00:00
79cae648e4
- Add expires_at check to ApprovePairing SELECT (PG + SQLite) to close race between prune DELETE and code lookup - Add isValidSenderID regex validation to handleRequest, handleRevoke, and handleBrowserPairingStatus (prevents log injection / bus poisoning) - Add slog.Warn on decrypt fallback paths for downgrade detection - Remove Slack compound senderID|displayName format; all channels now pass plain senderID with displayName in metadata