04f291910ff7c2893fe4dbb24395a28565d22e55
- All requests now require HTTPS. - Stateless sessions enabled for JWT-based auth. - XSS, HSTS, and Frame-Options headers added. - /api/auth/** is public, all other routes require authentication. - CSRF disabled (assumes token-based auth).
Description
Languages
Java
99.2%
Dockerfile
0.8%