/api/los proxy HMAC-signs identity headers

Featurekamo-internal
Dikirim
28 Mei 2026 pukul 23.53 UTC
Penulis
kamo
Commit
f0e813f

When LOS_PROXY_HMAC_SECRET env var is set, the proxy now computes **************** secret) and sends X-Proxy-Signature + X-Proxy-Timestamp alongside the X-Org-Id / X-Member-Id headers. KamoLOS's new ProxyHmacFilter validates this (±60s skew, constant-time compare) so a client bypassing kamo-internal can no longer spoof identity headers. Unset secret = local-dev pass-through (filter disabled on the backend side too).

Semua perubahan

Seperti apa yang Anda lihat pengiriman?

Semua pembaruan ini secara otomatis mendarat di ruang kerja Anda. Mulai bebas dan menontonnya tumbuh minggu demi minggu.

Mulai Bebas SelamanyaTampilkan Harga