3 Commits
Author SHA1 Message Date
Keith SmithandClaude Sonnet 4.5 e7fbef75e9 Fix HIGH Security Issue: Require ALLOWED_HOSTS in production
Added validation to ensure ALLOWED_HOSTS is explicitly set in production.

Changes:
- Check if ALLOWED_HOSTS environment variable is set
- Raise ValueError with helpful message if not set
- Use os.environ['ALLOWED_HOSTS'] instead of .get() to enforce requirement
- Prevents empty or missing ALLOWED_HOSTS from bypassing host validation

Security impact:
- Prevents host header injection attacks
- Blocks cache poisoning via host header manipulation
- Ensures production deployments have explicit allowed hosts configured
- Fails fast with clear error message if misconfigured

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2025-12-23 06:23:34 -07:00
Keith SmithandClaude Sonnet 4.5 026259b4f4 Fix HIGH Security Issue: Add comprehensive security headers
Added comprehensive security headers to prevent XSS, clickjacking, and other attacks.

Security Headers Added:
- SECURE_BROWSER_XSS_FILTER: Enable XSS filter
- SECURE_CONTENT_TYPE_NOSNIFF: Prevent MIME-type sniffing
- X_FRAME_OPTIONS: DENY to prevent clickjacking
- SECURE_REFERRER_POLICY: Control referrer information

Cookie Security:
- SESSION_COOKIE_HTTPONLY: Prevent JavaScript access to session cookies
- SESSION_COOKIE_SAMESITE: Strict to prevent CSRF
- CSRF_COOKIE_HTTPONLY: Prevent JavaScript access to CSRF tokens
- CSRF_COOKIE_SAMESITE: Strict protection

Content Security Policy (CSP):
- CSP_DEFAULT_SRC: Only allow same-origin resources
- CSP_SCRIPT_SRC: Restrict script execution to same-origin
- CSP_STYLE_SRC: Restrict stylesheets to same-origin
- CSP_IMG_SRC: Allow images from same-origin, data URIs, and HTTPS
- CSP_FRAME_ANCESTORS: Prevent embedding in iframes ('none')
- CSP_FORM_ACTION: Restrict form submissions to same-origin

CSRF Protection:
- Added CSRF_TRUSTED_ORIGINS configuration for cross-origin requests

Security impact:
- Prevents clickjacking attacks
- Mitigates XSS vulnerabilities
- Blocks MIME-type confusion attacks
- Protects cookies from JavaScript theft
- Enforces strict CSP to prevent code injection

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2025-12-23 06:22:14 -07:00
Keith SmithandClaude Sonnet 4.5 6a0b35c39c Initial commit: KeepItGoing task management server
Features:
- Django-based REST API with web interface
- Task management with tags, priorities, and due dates
- Time tracking with start/stop timers
- Subtasks support
- Task filtering (all, today, upcoming, overdue, completed)
- Tag-based organization with color coding
- Sorting by due date and priority
- Auto-assign tags when filtering
- Responsive 3-pane layout (sidebar, task list, detail panel)
- Task sharing between users
- Mobile-responsive design with dark mode support

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2025-12-18 17:41:29 -07:00