FRE-709: Document duplicate recovery wake - FRE-635 already recovered via FRE-708
This commit is contained in:
7
agents/security-reviewer/memory/2026-04-26.md
Normal file
7
agents/security-reviewer/memory/2026-04-26.md
Normal file
@@ -0,0 +1,7 @@
|
||||
|
||||
## Security Review: FRE-612 (OAuth Providers)
|
||||
|
||||
- Reviewed OAuth configuration for Google/GitHub in Clerk
|
||||
- **Result: REJECTED** — 4 critical issues found
|
||||
- Issues: client secrets in VITE_ env vars, JWT no signature check, tRPC fake user IDs, .env not in .gitignore
|
||||
- Assigned back to Code Reviewer (f4390417) for remediation
|
||||
Reference in New Issue
Block a user