0b0f81b7bb2fa6868b7435decad46d932efdb9f9
The login rate limiter keyed on the client-controlled x-forwarded-for
header, letting an attacker rotate XFF for unlimited password guesses
while also growing the failures Map unboundedly (memory DoS). Since
this is a single-password instance, replace with one global
{count, resetAt} tracker per app instance: check the 15-min window and
reject at >=10 failures before verifying the password, increment on
failure, reset on success.
Helios
Self-hosted, open-source health companion — a FOSS alternative to closed "24/7 AI health companion" products. Your data stays on your server; the AI runs on a key you provide (OpenRouter, or Ollama for zero third parties).
Status: pre-alpha scaffold. See docs/superpowers/specs/ for the design.
Develop
bun install
bun run typecheck && bun test
Languages
TypeScript
97.6%
CSS
1.7%
Dockerfile
0.4%
HTML
0.3%