Roadmap

Done In STYGION Web Infrastructure Bezpečnost

Security headers and OAuth redirect

CSP, HSTS and Cross-Origin-Opener-Policy on the web; OAuth error paths only allowlisted redirects (no open redirect).

Added
16 July 2026
Finished
16 July 2026

Opens the feedback panel with this card attached, and lands in the same queue as everything else.