Conversation
- Stopped trusting the X-Forwarded-For header blindly in RateLimitingFilter - Restricted proxy IP detection to trusted reverse proxy sources only - Prevented potential brute-force bypass on /sign-in and /sign-up routes
- Sanitized request URLs in WeatherApiClient.fetchJsonNode() before logging - Redacted the 'appid' query parameter on error paths to prevent writing the API key to application logs during parse failures or non-2xx responses
security: harden application runtime, session management, and client headers
…ints feat: implement database-to-API pagination layer for users and locations
- add `units` column to the users table via Liquibase changeset - default existing rows to metric
- add °C→°F and m/s→mph conversion at the presentation boundary - round to one decimal place, half-up, so values don't display raw floating-point artifacts
feat: implement user-centric measurement unit preference system across database, API, and UI
…count-lockout feat: implement Resilience4j fault tolerance and automated account lockout security
…n-cap fix: optimize rate-limiting scope, enhance weather fallback error handling, and enforce location limits
Add remember-me, email verification/password reset, account lockout, unit preference, dark mode, admin pagination, weather API resilience, and rate-limit hardening to the feature list. Add Observability, Security, and CI/CD sections; update env var docs and project structure to match.
…t for new constructors
feat: decouple email delivery with application events, asynchronous execution, and Resilience4j retries
…dd uk/fallback cases
feat(i18n): implement internationalization, Ukrainian localization support, and bump version to v1.2.0
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
This release PR merges all features, security hardening, performance optimizations, fault tolerance enhancements, and localization updates implemented in
devintomainfor the v1.2.0 production rollout.🔗 Merged Feature PRs Included in this Release
🚀 Key Summary of Changes
Internationalization & Localization (i18n):
MessageSourcebundles supporting English and Ukrainian (messages_uk.properties).Account Security & User Management:
persistent_logins).Secure,SameSite=Strict),Content-Security-Policyheaders, and capped active sessions to 1 per user.Resilience & Asynchronous Notifications:
@TransactionalEventListener).Performance & Data Optimization:
Pageable) for Users and Locations with an upper limit bound of 100 entries.DevOps & Infrastructure: