Ken Yasue
3dc0318011
fix: post-M4 validation improvements
- Session: verify server-side iat expiry (not just cookie maxAge)
- Validate ProjectMemberRole on member add (reject arbitrary strings)
- Scope coverage threshold to Repository/Service layers (per guidelines)
- Add session expiry/fresh-token unit tests
2026-06-25 01:11:35 +02:00
..
2026-06-25 01:02:10 +02:00
2026-06-25 01:11:35 +02:00
2026-06-25 00:21:26 +02:00
2026-06-24 23:53:30 +02:00
2026-06-25 01:11:35 +02:00
2026-06-25 00:36:42 +02:00