# Security Checklist - Passwords are hashed with `bcryptjs` before storage. - Provider API credentials are read only from environment variables and are never returned by public APIs. - Money columns use SQL `DECIMAL`; JavaScript money math uses fixed-scale `BigInt` helpers in `src/utils/money.js`. - Request bodies are validated server-side with `zod`. - SQL access goes through Knex query builders and transactions. - Auth, password reset, deposit creation, and order creation have rate limiting. - Every `/admin/*` route is protected by `auth`, `requireActive`, and `admin` middleware. - Admin self-ban and last-active-admin lockout are rejected. - Order prices are calculated on the server from `services.sell_price`; client-submitted prices are ignored. - Production environment validation rejects missing or placeholder provider/JWT settings and requires `CORS_ORIGIN`. - Production CORS allows only configured site origins. - Wallet balance updates are centralized in `wallet.service.js` and covered by race-condition tests.