Block a user
[Debt] Refactor high-complexity audit listing endpoints
[Debt] Refactor high-complexity admin catalog/settings route helpers
[Debt] Refactor high-complexity access directory/RBAC/admin flows
[Debt] Refactor high-complexity campaign validation, sending, and reporting code
[Security] Harden campaign WebUI dynamic regex and path assignment helpers
[Debt] Refactor high-complexity mail profile and transport functions
[Security] Review mail policy SQL text and wildcard regex audit findings
[Debt] Refactor high-complexity files connector and transfer flows
[Security] Run SMB connector dev container as non-root where feasible
[Security] Parse WebDAV XML with defusedxml
[Security] Parse WebDAV XML with defusedxml
[Security] Parse WebDAV XML with defusedxml
Codex state update: Implemented locally: WebDAV multistatus parsing now uses defusedxml.ElementTree.fromstring, with defusedxml>=0.7,<1 added to pyproject.toml. Verified with py_compile and…
[Debt] Refactor high-complexity calendar sync and VEVENT code
[Security] Add explicit egress policy to calendar sync URL fetches
[Debt] Refactor high-complexity core installer/configuration/runtime functions
[Security] Parse CalDAV and EWS XML with defusedxml
[Security] Parse CalDAV and EWS XML with defusedxml
Codex state update: Implemented locally: CalDAV and EWS XML parse paths now use defusedxml.ElementTree.fromstring, with defusedxml>=0.7,<1 added to pyproject.toml. Verified with py_compile…
[Security] Parse CalDAV and EWS XML with defusedxml
[Security] Lock audit toolbox dependencies flagged by OSV
[Security] Fix audit report capture and duplicate-scan noise