clusev/docs/superpowers/specs
boban 9756f9d463 docs: implementation plan — control-plane brute-force ban (Anmeldeschutz)
9-task TDD plan: BannedIp model, BruteforceGuard (inet_pton CIDR + cache),
ValidIpOrCidr rule, guests-only BlockBannedIp middleware + 403 page, Login/2FA
failure hooks + audit, clusev:unban CLI, Anmeldeschutz settings tab with R5
confirm-modal unban. Spec erratum: middleware is appended (not prepended) so
Auth::guest() resolves for the guests-only check.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-20 17:20:52 +02:00
..
2026-06-14-account-recovery-design.md docs(spec): account recovery design (forgot-password, 2FA backup codes, CLI) 2026-06-14 16:41:45 +02:00
2026-06-14-accounts-sessions-restart-design.md docs(spec): 0.9.0 accounts, sessions, auto-restart, SMTP, audit-retention 2026-06-14 23:17:41 +02:00
2026-06-14-external-proxy-tls-design.md docs(spec): external reverse-proxy TLS mode (Zoraxy in front) 2026-06-14 22:26:20 +02:00
2026-06-14-optional-pluggable-2fa-design.md docs(spec): optional, pluggable 2FA (TOTP and/or YubiKey) design 2026-06-14 19:47:55 +02:00
2026-06-14-server-details-hardening-polish-design.md docs(spec): server-details UX + hardening polish design 2026-06-14 10:09:17 +02:00
2026-06-14-ssh-key-auto-provision-design.md docs(spec): auto-provision SSH key & safely disable password login 2026-06-14 21:54:02 +02:00
2026-06-14-webauthn-yubikey-design.md docs(spec): WebAuthn/YubiKey 2nd-factor design (Phase 2) 2026-06-14 18:12:32 +02:00
2026-06-15-confirm-action-token-hardening-design.md feat(security): signed confirm-action tokens + airtight backup-code reveal 2026-06-15 18:35:33 +02:00
2026-06-15-de-claude-history-rewrite-design.md docs(spec): de-Claude repo + git-history rewrite runbook (beta-prep #2) 2026-06-15 19:30:23 +02:00
2026-06-15-forgot-password-smtp-aware-design.md docs(spec): SMTP-aware forgot-password (15-min link + 2FA fallback) 2026-06-15 18:47:53 +02:00
2026-06-15-installer-overhaul-design.md docs(spec): installer overhaul (Docker install, clusev user, DNS check) + themed MOTD 2026-06-15 19:07:52 +02:00
2026-06-15-recovery-codes-airtight-reveal-design.md fix(2fa): bound the backup-code reveal flag with a 10-minute TTL 2026-06-15 18:42:58 +02:00
2026-06-17-request-certificate-button-design.md docs(spec): dashboard "request certificate" button (trigger Caddy on-demand TLS) 2026-06-17 18:24:25 +02:00
2026-06-19-clusev-cli-and-command-shortcuts-design.md docs: spec for clusev host CLI, short commands, help tab-URL 2026-06-19 22:37:37 +02:00
2026-06-19-help-page-design.md docs(spec): in-panel Help page design + drop product name from external-proxy hint 2026-06-19 22:02:25 +02:00
2026-06-20-2fa-challenge-backup-view-design.md fix(auth): R15 review — restore one-time-code autofill, memoise pendingUser in verify 2026-06-20 16:19:40 +02:00
2026-06-20-control-plane-bruteforce-ban-design.md docs: implementation plan — control-plane brute-force ban (Anmeldeschutz) 2026-06-20 17:20:52 +02:00