| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-04-26 | 1.5 kB | |
| v0.2.0 source code.tar.gz | 2026-04-26 | 641.2 kB | |
| v0.2.0 source code.zip | 2026-04-26 | 686.8 kB | |
| Totals: 3 Items | 1.3 MB | 0 | |
What's new in v0.2.0
Added
- Admin session expiry warning — banner appears 5 minutes before session expires with live countdown and one-click extend
- Dashboard pagination, sorting & filtering — server-side pagination (10/25/50/100 per page), sort by any column, filter by status with stat card shortcuts
- File attachments — whistleblowers can upload evidence (PDF, images, Word, Excel, CSV, TXT — up to 10 MB each, 5 per report)
- Email & webhook notifications — get notified when a new report is submitted (
NOTIFY_EMAIL_*/NOTIFY_WEBHOOK_*) - CSRF protection extended to all whistleblower POST endpoints (
/submit,/status,/reply) scripts/reset_admin_password.py— interactive CLI to reset admin passwords without direct DB access- Company branding, OIDC login, professional dark mode, Docker image cleanup workflow
Fixed
- Orphaned whistleblower Redis session keys now cleaned up on report deletion
- SLA column no longer shows double unit ("89d Tage verbleibend")
- Session cookie deletion passes correct security attributes
- Theme toggle uses correct body font
- Public forms now enforce
requiredfield validation in the browser
Security
- Whistleblower cookies now use
secure=not DEMO_MODE(was hardcodedFalse) - Server-side max-length enforced for descriptions (10 000 chars) and replies (5 000 chars)
- CSRF protection on all whistleblower POST endpoints
See CHANGELOG.md for the full list of changes.