-
Notifications
You must be signed in to change notification settings - Fork 14
Issues: FusionAuth/fusionauth-issues
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
[Enhancement Request] [Security]: Please support Geo Fencing of FusionAuth EndPoints
cloud
enhancement
New feature or request
security
#3016
opened Mar 11, 2025 by
bbarman4u
Add better content security policy support to admin pages
security
#2813
opened Jul 23, 2024 by
andrewpai
Potential email enumeration via new "Confirmation required" page
bug
Something isn't working
security
#2694
opened Mar 21, 2024 by
spwitt
Create allow list and deny list configurations for hosts in fetch calls using the Graal engine
enhancement
New feature or request
external-configuration
security
#2549
opened Nov 13, 2023 by
lyleschemmerling
Add IdP policy to never trust email, and perform inline email verification on link
security
#2506
opened Oct 11, 2023 by
robotdan
Updates to self-service session management
enhancement
New feature or request
security
#2425
opened Aug 14, 2023 by
robotdan
3 tasks
Add additional linking strategy for email and username to link only if user does not yet exist
enhancement
New feature or request
security
#2424
opened Aug 14, 2023 by
robotdan
Increase the default factor for PBKDF2 based password hashing schemes
enhancement
New feature or request
security
#2366
opened Jul 10, 2023 by
mooreds
Dead end email verification gate when logging in via IdP
security
#2334
opened Jun 20, 2023 by
robotdan
Lambda enhancements, environments, secrets and fetch config
enhancement
New feature or request
security
#1629
opened Mar 10, 2022 by
robotdan
1 of 5 tasks
Hide other secrets in the UI behind a POST to reveal button
security
#1059
opened Jan 8, 2021 by
robotdan
2 of 10 tasks
Use statuscode 303 instead of 302 for redirects
oauth2.1
security
#806
opened Aug 12, 2020 by
JuliusPC
Inline javascript on login page must be blocked for secure content security policy
architecture
Feedback on designed behavior
security
#634
opened May 16, 2020 by
awesomizer
ProTip!
Mix and match filters to narrow down what you’re looking for.