1.0 KiB
1.0 KiB
Security Checklist
- Passwords are hashed with
bcryptjsbefore storage. - Provider API credentials are read only from environment variables and are never returned by public APIs.
- Money columns use SQL
DECIMAL; JavaScript money math uses fixed-scaleBigInthelpers insrc/utils/money.js. - Request bodies are validated server-side with
zod. - SQL access goes through Knex query builders and transactions.
- Auth, password reset, deposit creation, and order creation have rate limiting.
- Every
/admin/*route is protected byauth,requireActive, andadminmiddleware. - Admin self-ban and last-active-admin lockout are rejected.
- Order prices are calculated on the server from
services.sell_price; client-submitted prices are ignored. - Production environment validation rejects missing or placeholder provider/JWT settings and requires
CORS_ORIGIN. - Production CORS allows only configured site origins.
- Wallet balance updates are centralized in
wallet.service.jsand covered by race-condition tests.