- Dockerfile: non-root user appuser, chown /data + /app - media_utils: validate_upload() Magic-Byte-Check (JPEG/PNG/GIF/WebP/MP4/WebM) - media_utils: safe_media_path() Path-Traversal-Schutz beim Löschen - diary/health/dogs: safe_media_path() statt os.path.join + lstrip - diary: validate_upload() vor jedem Medien-Upload - forum: _LIKE_TABLE dict statt dynamischer String-Interpolation - requirements: uvicorn 0.34, PyJWT 2.10.1, pydantic 2.10.6, bcrypt 4.3, httpx 0.28.1, anthropic 0.49 - SW by-v319, APP_VER 307
13 lines
239 B
Text
13 lines
239 B
Text
fastapi==0.115.0
|
|
Pillow==11.2.1
|
|
pillow-heif==0.22.0
|
|
uvicorn[standard]==0.34.0
|
|
python-multipart==0.0.20
|
|
pydantic[email]==2.10.6
|
|
bcrypt==4.3.0
|
|
PyJWT==2.10.1
|
|
httpx==0.28.1
|
|
openai==1.50.0
|
|
anthropic==0.49.0
|
|
pywebpush==2.0.0
|
|
apscheduler==3.10.4
|