# backend/.env
JWT_SECRET=<your-64-character-random-secret>
MONGO_ROOT_PASSWORD=<strong-database-password>
SESSION_SECRET=<another-random-secret>
SERVER_ENV=productionGenerate secrets:
# Generate 64-char secret
openssl rand -base64 64
# Or use: https://randomkeygen.com/- β JWT tokens (access + refresh)
- β Bcrypt password hashing (cost: 12)
- β Token expiration (24 hours default)
- β Secure password requirements
- β User isolation (users can't access others' data)
- β Project ownership validation
- β Admin role support
- β Protected endpoints
- β X-Frame-Options: DENY
- β X-Content-Type-Options: nosniff
- β X-XSS-Protection: 1; mode=block
- β Content-Security-Policy
- β CORS configuration
- β 100 requests/minute per IP (default)
- β Configurable via environment
- β 429 response on limit exceeded
- β Request validation
- β Email format validation
- β Password strength requirements
- β MongoDB injection prevention
- β No sensitive data in error messages
- β Panic recovery
- β Structured error logging
- β Generic error responses
# Security
JWT_SECRET=<random-64-chars> # REQUIRED
SESSION_SECRET=<random-64-chars> # REQUIRED
BCRYPT_COST=12 # Recommended: 10-14
# Database
MONGO_URI=mongodb://user:pass@host:port # Use strong password
MONGO_DB=blueprint # Your DB name
# Server
SERVER_ENV=production # IMPORTANT!
SERVER_PORT=8080
CORS_ORIGIN=https://your-domain.com # Your frontend URL
# Rate Limiting
RATE_LIMIT_ENABLED=true
RATE_LIMIT_REQUESTS_PER_MINUTE=100
# Logging
LOG_LEVEL=info # Don't use 'debug' in production
LOG_FORMAT=jsonCurrent Rules:
- Minimum: 8 characters
- Maximum: 72 characters (bcrypt limit)
- Required: Mix of letters & numbers recommended
Enforce in validation:
// backend validation already includes:
validate:"required,min=8,max=72"- Change all default secrets
- Use HTTPS in production
- Set proper CORS origins
- Keep dependencies updated
- Use strong database passwords
- Enable rate limiting
- Review logs regularly
- Use environment variables for secrets
- Commit secrets to Git
- Use default passwords
- Expose admin endpoints publicly
- Allow unlimited requests
- Return detailed errors to users
- Use weak JWT secrets
- Run as root in Docker
- Disable security features
- Changed JWT_SECRET
- Changed MONGO_ROOT_PASSWORD
- Changed SESSION_SECRET
- Set SERVER_ENV=production
- Configured proper CORS_ORIGIN
- Using HTTPS
- Rate limiting enabled
- Strong database password
- Reviewed exposed ports
- No secrets in code/Git
- Updated all dependencies
- Enabled security headers
- Configured proper logging
- Set up monitoring/alerts
- DO NOT create a public issue
- Email: [your-security-email]
- Include:
- Description of vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We'll respond within 48 hours.
| Date | Action | Status |
|---|---|---|
| 2025-11-28 | Phase 1 Security Fixes | β Complete |
| 2025-11-28 | Authorization Implementation | β Complete |
| 2025-11-28 | Security Testing | β 27/27 tests passing |
| 2025-11-28 | Code Coverage | β 78.1% |
- Review access logs
- Check for failed login attempts
- Monitor rate limit hits
- Update dependencies (
go get -u,npm update) - Review user permissions
- Check for CVEs in dependencies
- Full security audit
- Penetration testing
- Review and update secrets
- Security training
# Vulnerability scan
govulncheck ./...
# Security audit
gosec ./...
# Dependencies
go list -m all | nancy sleuth# Audit dependencies
npm audit
# Fix auto-fixable issues
npm audit fix
# Check for outdated packages
npm outdatedLast Updated: 2025-11-28
Security Status: β
Hardened