Files
SS/SECURITY.md
T

1.0 KiB

Security Checklist

  • Passwords are hashed with bcryptjs before storage.
  • Provider API credentials are read only from environment variables and are never returned by public APIs.
  • Money columns use SQL DECIMAL; JavaScript money math uses fixed-scale BigInt helpers in src/utils/money.js.
  • Request bodies are validated server-side with zod.
  • SQL access goes through Knex query builders and transactions.
  • Auth, password reset, deposit creation, and order creation have rate limiting.
  • Every /admin/* route is protected by auth, requireActive, and admin middleware.
  • Admin self-ban and last-active-admin lockout are rejected.
  • Order prices are calculated on the server from services.sell_price; client-submitted prices are ignored.
  • Production environment validation rejects missing or placeholder provider/JWT settings and requires CORS_ORIGIN.
  • Production CORS allows only configured site origins.
  • Wallet balance updates are centralized in wallet.service.js and covered by race-condition tests.