c0eb1de7a7
Build & Push / Pipeline Tests (push) Successful in 2m1s
Test / Type Check (all packages) (push) Successful in 53s
Build & Push / Build & Push Docker Image (push) Successful in 5m29s
Test / API Unit Tests (push) Successful in 1m18s
Test / Homepage Unit Tests (push) Successful in 46s
Test / Carplace Unit Tests (push) Successful in 43s
Test / Admin Unit Tests (push) Successful in 40s
Test / Dashboard Unit Tests (push) Successful in 42s
Test / API Integration Tests (push) Successful in 1m9s
42 lines
3.4 KiB
Markdown
42 lines
3.4 KiB
Markdown
# Security Hardening Applied
|
|
|
|
This bundle applies the highest-risk items from the hardened security fix plan to the uploaded apps source.
|
|
|
|
## Applied changes
|
|
|
|
- Added explicit subscription read/write/full middleware and moved sensitive mutations to write/full checks.
|
|
- Hardened backend route authorization for reservations, customers, vehicles, analytics, payments, reviews, complaints, team, companies, offers, notifications, billing, and subscription actions.
|
|
- Blocked AGENT access to manager/owner actions including reservation lifecycle transitions, analytics, payments, review replies/reminders, team lists/stats, license image reads, license validation, and complaint mutations.
|
|
- Disabled public Swagger/OpenAPI exposure in production unless `ENABLE_PUBLIC_API_DOCS=true` is explicitly set.
|
|
- Added CSRF-style Origin/Referer enforcement for cookie-authenticated browser mutations.
|
|
- Added forwarding-header sanitization middleware and stripped spoofable forwarding headers from the dashboard API proxy.
|
|
- Changed dashboard redirects to use the configured canonical dashboard URL instead of request-supplied forwarded host headers.
|
|
- Blocked anonymous `/storage` access to reservation photo paths and classified reservation uploads as private storage.
|
|
- Tightened image upload limits, file count limits, magic-byte validation, extension consistency, and basic image dimension limits.
|
|
- Added a dedicated webhook rate limiter and raw body size limits.
|
|
- Hardened AmanPay webhook signature verification so invalid signature length returns false instead of throwing.
|
|
- Hardened webhook idempotency by rejecting missing provider event IDs and allowing stale PROCESSING records to retry after a timeout.
|
|
- Hardened PayPal capture by binding capture to company, reservation, local pending payment status, provider completion status, amount, and currency.
|
|
- Restricted public site/carplace booking flows to ACTIVE/TRIALING companies and AVAILABLE published vehicles.
|
|
- Capped public Carplace pagination and metadata size.
|
|
- Replaced rank-only admin role checks with explicit role allowlists so SUPPORT no longer implicitly outranks FINANCE.
|
|
- Required fresh admin 2FA before replacing an already-enabled admin TOTP setup.
|
|
- Started storing admin reset tokens and employee email verification tokens as hashes while preserving legacy raw-token lookup during migration.
|
|
|
|
## Validation performed
|
|
|
|
The sandbox did not include a usable installed workspace dependency tree, so full `npm test` / `npm run type-check` could not be executed from the extracted bundle. A TypeScript syntactic transpile check was run against all changed TypeScript files and passed.
|
|
|
|
## Important remaining work
|
|
|
|
This patch does not fully complete every item in the hardening plan. The remaining work should be handled before production sign-off:
|
|
|
|
- Add/expand DB-backed audit logging for every sensitive mutation.
|
|
- Add database-backed idempotency for public booking instead of the current process-local cache.
|
|
- Add full route authorization matrix tests across unauthenticated, AGENT, MANAGER, OWNER, wrong tenant, suspended, paused, and past-due states.
|
|
- Add storage migration scripts to move existing public reservation photos into private storage.
|
|
- Finish token migration for review tokens and any remaining invitation/public access tokens if schema support exists.
|
|
- Add full payment provider merchant/receiver-account validation if provider config is stored per company.
|
|
- Add dependency/lockfile CI gates from the plan.
|
|
|