c6504f70d1
- Rewrite keyboard shortcuts using e.code and early preventDefault() to reliably override browser defaults - Add ? key and toolbar button for shortcuts help modal - Add password strength meter to register form - Add search highlighting in all view modes (grid/list/compact/table) - Add hash-based color coding for folder chips - Add highlightText utility with regex escaping
661 B
661 B
Remaining Security Issues
- No rate limiting on
/reauth— brute-force possible via export dialog - No Content Security Policy (CSP) header — XSS could leak crypto key from sessionStorage
- Crypto key in sessionStorage (extractable) — necessary for refresh persistence, but XSS can steal it. HttpOnly cookie + service worker is more secure but complex
- No session rotation — same token until logout; if leaked, valid for 24h
- No 2FA — opted out of TOTP implementation
- Password generator modulo bias —
c.charAt(arr[i] % c.length)has slight bias when c.length does not divide 2^32; not practically exploitable