Summary
Track remediation work from local Kratos security review.
Already done
Remaining actions
Acceptance criteria
- No hardcoded secrets remain in tracked files
- Local and production configs both run without secret leakage in logs
/admin/* returns 403 for authenticated non-admin users
- Security checklist documented in repo docs
Summary
Track remediation work from local Kratos security review.
Already done
DSN) usage/admin/*inbackend/main.gokratos/kratos-production.ymlto.gitignoredocker-compose.yml)Remaining actions
log.leak_sensitive_values: falsein localkratos/kratos.yml12in active configsmetadata_admin.rolepreferred) and document onboarding for admin usersDSNbeforekratos serveandkratos migrateAcceptance criteria
/admin/*returns403for authenticated non-admin users