## Phase 8: Enterprise Extractor Improvements ✅ - 14 security extractors (TLS, JWT, SQL injection, XSS, etc.) - 10 framework-specific extractors (Spring, Django, Rails, etc.) - Config file security detection (YAML, TOML) ## Phase 9: Autonomous Extractor Generation ✅ - Shadow mode executor with TP/FP tracking - Graduation pipeline with confidence thresholds - Auto-rollback on regression detection - Cross-project pattern syncing ## UAT Suite Complete (14 scripts, 90 tests) - test-core-detection.sh (6 tests) - test-declarative-extractors.sh (5 tests) - test-domain-frameworks.sh (5 tests) - test-domain-unreal.sh (3 tests) - test-llm-extraction.sh (6 tests) - test-eval-harness.sh (5 tests) - test-cross-language.sh (3 tests) - test-precommit-performance.sh (4 tests) - test-output-formats.sh (8 tests) - test-drift-detection.sh (6 tests) - test-exit-codes.sh (12 tests) + 3 more scripts ## Other Changes - Updated roadmap to mark Phase 8-9 complete - Added .gitignore entries for build artifacts - Updated pre-commit: 800 line limit, exclude tests/data/cmd Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
23 lines
401 B
JavaScript
23 lines
401 B
JavaScript
const express = require('express');
|
|
const cors = require('cors');
|
|
const session = require('express-session');
|
|
|
|
const app = express();
|
|
|
|
// BAD: CORS with wildcard origin and credentials
|
|
app.use(cors({
|
|
origin: '*',
|
|
credentials: true
|
|
}));
|
|
|
|
app.use(session({
|
|
secret: 'keyboard cat',
|
|
resave: false,
|
|
cookie: {
|
|
secure: false,
|
|
httpOnly: false
|
|
}
|
|
}));
|
|
|
|
app.listen(3000);
|