Initial SMM panel implementation
This commit is contained in:
+14
@@ -0,0 +1,14 @@
|
||||
# Security Checklist
|
||||
|
||||
- Passwords are hashed with `bcryptjs` before storage.
|
||||
- Provider API credentials are read only from environment variables and are never returned by public APIs.
|
||||
- Money columns use SQL `DECIMAL`; JavaScript money math uses fixed-scale `BigInt` helpers in `src/utils/money.js`.
|
||||
- Request bodies are validated server-side with `zod`.
|
||||
- SQL access goes through Knex query builders and transactions.
|
||||
- Auth, password reset, deposit creation, and order creation have rate limiting.
|
||||
- Every `/admin/*` route is protected by `auth`, `requireActive`, and `admin` middleware.
|
||||
- Admin self-ban and last-active-admin lockout are rejected.
|
||||
- Order prices are calculated on the server from `services.sell_price`; client-submitted prices are ignored.
|
||||
- Production environment validation rejects missing or placeholder provider/JWT settings and requires `CORS_ORIGIN`.
|
||||
- Production CORS allows only configured site origins.
|
||||
- Wallet balance updates are centralized in `wallet.service.js` and covered by race-condition tests.
|
||||
Reference in New Issue
Block a user