 131868bdca
			
		
	
	131868bdca
	
	
	
		
			
			Major security, observability, and configuration improvements:
## Security Hardening
- Implemented configurable CORS (no more wildcards)
- Added comprehensive auth middleware for admin endpoints
- Enhanced webhook HMAC validation
- Added input validation and rate limiting
- Security headers and CSP policies
## Configuration Management
- Made N8N webhook URL configurable (WHOOSH_N8N_BASE_URL)
- Replaced all hardcoded endpoints with environment variables
- Added feature flags for LLM vs heuristic composition
- Gitea fetch hardening with EAGER_FILTER and FULL_RESCAN options
## API Completeness
- Implemented GetCouncilComposition function
- Added GET /api/v1/councils/{id} endpoint
- Council artifacts API (POST/GET /api/v1/councils/{id}/artifacts)
- /admin/health/details endpoint with component status
- Database lookup for repository URLs (no hardcoded fallbacks)
## Observability & Performance
- Added OpenTelemetry distributed tracing with goal/pulse correlation
- Performance optimization database indexes
- Comprehensive health monitoring
- Enhanced logging and error handling
## Infrastructure
- Production-ready P2P discovery (replaces mock implementation)
- Removed unused Redis configuration
- Enhanced Docker Swarm integration
- Added migration files for performance indexes
## Code Quality
- Comprehensive input validation
- Graceful error handling and failsafe fallbacks
- Backwards compatibility maintained
- Following security best practices
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
		
	
		
			
				
	
	
		
			74 lines
		
	
	
		
			2.1 KiB
		
	
	
	
		
			Go
		
	
	
	
	
	
			
		
		
	
	
			74 lines
		
	
	
		
			2.1 KiB
		
	
	
	
		
			Go
		
	
	
	
	
	
| // Copyright 2018 The Go Authors. All rights reserved.
 | |
| // Use of this source code is governed by a BSD-style
 | |
| // license that can be found in the LICENSE file.
 | |
| 
 | |
| package cpu
 | |
| 
 | |
| const cacheLineSize = 32
 | |
| 
 | |
| // HWCAP/HWCAP2 bits.
 | |
| // These are specific to Linux.
 | |
| const (
 | |
| 	hwcap_SWP       = 1 << 0
 | |
| 	hwcap_HALF      = 1 << 1
 | |
| 	hwcap_THUMB     = 1 << 2
 | |
| 	hwcap_26BIT     = 1 << 3
 | |
| 	hwcap_FAST_MULT = 1 << 4
 | |
| 	hwcap_FPA       = 1 << 5
 | |
| 	hwcap_VFP       = 1 << 6
 | |
| 	hwcap_EDSP      = 1 << 7
 | |
| 	hwcap_JAVA      = 1 << 8
 | |
| 	hwcap_IWMMXT    = 1 << 9
 | |
| 	hwcap_CRUNCH    = 1 << 10
 | |
| 	hwcap_THUMBEE   = 1 << 11
 | |
| 	hwcap_NEON      = 1 << 12
 | |
| 	hwcap_VFPv3     = 1 << 13
 | |
| 	hwcap_VFPv3D16  = 1 << 14
 | |
| 	hwcap_TLS       = 1 << 15
 | |
| 	hwcap_VFPv4     = 1 << 16
 | |
| 	hwcap_IDIVA     = 1 << 17
 | |
| 	hwcap_IDIVT     = 1 << 18
 | |
| 	hwcap_VFPD32    = 1 << 19
 | |
| 	hwcap_LPAE      = 1 << 20
 | |
| 	hwcap_EVTSTRM   = 1 << 21
 | |
| 
 | |
| 	hwcap2_AES   = 1 << 0
 | |
| 	hwcap2_PMULL = 1 << 1
 | |
| 	hwcap2_SHA1  = 1 << 2
 | |
| 	hwcap2_SHA2  = 1 << 3
 | |
| 	hwcap2_CRC32 = 1 << 4
 | |
| )
 | |
| 
 | |
| func initOptions() {
 | |
| 	options = []option{
 | |
| 		{Name: "pmull", Feature: &ARM.HasPMULL},
 | |
| 		{Name: "sha1", Feature: &ARM.HasSHA1},
 | |
| 		{Name: "sha2", Feature: &ARM.HasSHA2},
 | |
| 		{Name: "swp", Feature: &ARM.HasSWP},
 | |
| 		{Name: "thumb", Feature: &ARM.HasTHUMB},
 | |
| 		{Name: "thumbee", Feature: &ARM.HasTHUMBEE},
 | |
| 		{Name: "tls", Feature: &ARM.HasTLS},
 | |
| 		{Name: "vfp", Feature: &ARM.HasVFP},
 | |
| 		{Name: "vfpd32", Feature: &ARM.HasVFPD32},
 | |
| 		{Name: "vfpv3", Feature: &ARM.HasVFPv3},
 | |
| 		{Name: "vfpv3d16", Feature: &ARM.HasVFPv3D16},
 | |
| 		{Name: "vfpv4", Feature: &ARM.HasVFPv4},
 | |
| 		{Name: "half", Feature: &ARM.HasHALF},
 | |
| 		{Name: "26bit", Feature: &ARM.Has26BIT},
 | |
| 		{Name: "fastmul", Feature: &ARM.HasFASTMUL},
 | |
| 		{Name: "fpa", Feature: &ARM.HasFPA},
 | |
| 		{Name: "edsp", Feature: &ARM.HasEDSP},
 | |
| 		{Name: "java", Feature: &ARM.HasJAVA},
 | |
| 		{Name: "iwmmxt", Feature: &ARM.HasIWMMXT},
 | |
| 		{Name: "crunch", Feature: &ARM.HasCRUNCH},
 | |
| 		{Name: "neon", Feature: &ARM.HasNEON},
 | |
| 		{Name: "idivt", Feature: &ARM.HasIDIVT},
 | |
| 		{Name: "idiva", Feature: &ARM.HasIDIVA},
 | |
| 		{Name: "lpae", Feature: &ARM.HasLPAE},
 | |
| 		{Name: "evtstrm", Feature: &ARM.HasEVTSTRM},
 | |
| 		{Name: "aes", Feature: &ARM.HasAES},
 | |
| 		{Name: "crc32", Feature: &ARM.HasCRC32},
 | |
| 	}
 | |
| 
 | |
| }
 |