>_
.issue.db
/issues
Dashboard
Issues
Memory
Lessons
Audit Log
New Issue
Edit Issue #41
Update issue details
Title *
Description
Signed HttpOnly session cookie on review GET + double-submit CSRF on all Action Web POSTs (UB-AW-6, UB-TOK-5, UN-SEC-2); OTP moves to Redis (hashed code, TTL, atomic attempts max 5, single-use); step-up decided by policy snapshot not client form field (current require_otp param is a bypass). Phase 1.
Priority
Low
Medium
High
Critical
Status
Open
In Progress
Closed
Won't Do
Due Date (YYYY-MM-DD)
Tags (comma separated)
Related Issues (IDs)
Enter IDs of issues related to this one. They will be linked as 'related'.
Update Issue
Cancel