SetIPChangeEnforce controls how the auth middleware reacts when a session's binding (client IP OR User-Agent hash) changes mid-lifetime: - mode == "strict": revoke the session and reject the request (the token is treated as possibly stolen). Covers BOTH the IP and the UA signal — one flag arms the w
(mode string)
| 938 | // PAD_IP_CHANGE_ENFORCE env var. See handleSessionIPChange / |
| 939 | // handleSessionUAChange for the per-signal semantics. |
| 940 | func (s *Server) SetIPChangeEnforce(mode string) { |
| 941 | s.ipChangeEnforceStrict = strings.EqualFold(strings.TrimSpace(mode), "strict") |
| 942 | } |
| 943 | |
| 944 | // reconfigureEmail reads email settings from the platform_settings table |
| 945 | // and updates (or creates) the email sender. Called after admin settings change. |
no outgoing calls