internal/core/security.go was preserved through Phase 0's auth prune untouched. Audit: zero callers anywhere in the codebase, yet the file kept golang.org/x/crypto as a direct dep and ran a full Argon2id KDF on every process start via a package-level init() that pre-computed a dummy hash "to prevent timing attacks" — wasted boot CPU for an unused codepath. Deleted symbols: - HashPassword, VerifyPassword, VerifyPasswordWithRehash - VerifyPasswordTimingSafe + dummyHash init() - decodeHash, needsRehash internal helpers - GenerateSecureToken, GenerateRefreshToken - HashToken, CompareTokenHash go mod tidy demotes golang.org/x/crypto from direct to indirect (pgx/v5 still pulls it transitively). Surfaced by the pre-Phase-5 cross-phase alignment audit. Cleared as part of finishing Phase 0's auth prune rather than logged as deferred work. BACKLOG closed section records the item + resolution. |
||
|---|---|---|
| .. | ||
| base64-tool | ||
| c2-beacon | ||
| caesar-cipher | ||
| canary-token-generator | ||
| dns-lookup | ||
| firewall-rule-engine | ||
| hash-cracker | ||
| keylogger | ||
| linux-cis-hardening-auditor | ||
| linux-ebpf-security-tracer | ||
| metadata-scrubber-tool | ||
| network-traffic-analyzer | ||
| simple-port-scanner | ||
| simple-vulnerability-scanner | ||
| systemd-persistence-scanner | ||