Skip to content

Security: madcok-co/blueprint

Security

SECURITY.md

πŸ”’ Security Guide

🚨 CRITICAL: Before Production

Must Change These Values!

# backend/.env
JWT_SECRET=<your-64-character-random-secret>
MONGO_ROOT_PASSWORD=<strong-database-password>
SESSION_SECRET=<another-random-secret>
SERVER_ENV=production

Generate secrets:

# Generate 64-char secret
openssl rand -base64 64

# Or use: https://randomkeygen.com/

βœ… Security Features (Already Implemented)

1. Authentication

  • βœ… JWT tokens (access + refresh)
  • βœ… Bcrypt password hashing (cost: 12)
  • βœ… Token expiration (24 hours default)
  • βœ… Secure password requirements

2. Authorization

  • βœ… User isolation (users can't access others' data)
  • βœ… Project ownership validation
  • βœ… Admin role support
  • βœ… Protected endpoints

3. Security Headers

  • βœ… X-Frame-Options: DENY
  • βœ… X-Content-Type-Options: nosniff
  • βœ… X-XSS-Protection: 1; mode=block
  • βœ… Content-Security-Policy
  • βœ… CORS configuration

4. Rate Limiting

  • βœ… 100 requests/minute per IP (default)
  • βœ… Configurable via environment
  • βœ… 429 response on limit exceeded

5. Input Validation

  • βœ… Request validation
  • βœ… Email format validation
  • βœ… Password strength requirements
  • βœ… MongoDB injection prevention

6. Error Handling

  • βœ… No sensitive data in error messages
  • βœ… Panic recovery
  • βœ… Structured error logging
  • βœ… Generic error responses

βš™οΈ Production Configuration

Environment Variables

# Security
JWT_SECRET=<random-64-chars>              # REQUIRED
SESSION_SECRET=<random-64-chars>          # REQUIRED
BCRYPT_COST=12                            # Recommended: 10-14

# Database
MONGO_URI=mongodb://user:pass@host:port   # Use strong password
MONGO_DB=blueprint                        # Your DB name

# Server
SERVER_ENV=production                     # IMPORTANT!
SERVER_PORT=8080
CORS_ORIGIN=https://your-domain.com       # Your frontend URL

# Rate Limiting
RATE_LIMIT_ENABLED=true
RATE_LIMIT_REQUESTS_PER_MINUTE=100

# Logging
LOG_LEVEL=info                            # Don't use 'debug' in production
LOG_FORMAT=json

πŸ” Password Requirements

Current Rules:

  • Minimum: 8 characters
  • Maximum: 72 characters (bcrypt limit)
  • Required: Mix of letters & numbers recommended

Enforce in validation:

// backend validation already includes:
validate:"required,min=8,max=72"

πŸ›‘οΈ Security Best Practices

βœ… DO:

  • Change all default secrets
  • Use HTTPS in production
  • Set proper CORS origins
  • Keep dependencies updated
  • Use strong database passwords
  • Enable rate limiting
  • Review logs regularly
  • Use environment variables for secrets

❌ DON'T:

  • Commit secrets to Git
  • Use default passwords
  • Expose admin endpoints publicly
  • Allow unlimited requests
  • Return detailed errors to users
  • Use weak JWT secrets
  • Run as root in Docker
  • Disable security features

πŸ” Security Checklist

Before Deployment

  • Changed JWT_SECRET
  • Changed MONGO_ROOT_PASSWORD
  • Changed SESSION_SECRET
  • Set SERVER_ENV=production
  • Configured proper CORS_ORIGIN
  • Using HTTPS
  • Rate limiting enabled
  • Strong database password
  • Reviewed exposed ports
  • No secrets in code/Git
  • Updated all dependencies
  • Enabled security headers
  • Configured proper logging
  • Set up monitoring/alerts

🚨 Vulnerability Response

If You Find a Security Issue:

  1. DO NOT create a public issue
  2. Email: [your-security-email]
  3. Include:
    • Description of vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

We'll respond within 48 hours.


πŸ“Š Security Audit Log

Date Action Status
2025-11-28 Phase 1 Security Fixes βœ… Complete
2025-11-28 Authorization Implementation βœ… Complete
2025-11-28 Security Testing βœ… 27/27 tests passing
2025-11-28 Code Coverage βœ… 78.1%

πŸ”„ Regular Security Tasks

Weekly:

  • Review access logs
  • Check for failed login attempts
  • Monitor rate limit hits

Monthly:

  • Update dependencies (go get -u, npm update)
  • Review user permissions
  • Check for CVEs in dependencies

Quarterly:

  • Full security audit
  • Penetration testing
  • Review and update secrets
  • Security training

πŸ› οΈ Security Tools

Backend

# Vulnerability scan
govulncheck ./...

# Security audit
gosec ./...

# Dependencies
go list -m all | nancy sleuth

Frontend

# Audit dependencies
npm audit

# Fix auto-fixable issues
npm audit fix

# Check for outdated packages
npm outdated

πŸ“š Resources


Last Updated: 2025-11-28
Security Status: βœ… Hardened

There aren't any published security advisories