Files
SS/SECURITY.md
T

15 lines
1.0 KiB
Markdown

# Security Checklist
- Passwords are hashed with `bcryptjs` before storage.
- Provider API credentials are read only from environment variables and are never returned by public APIs.
- Money columns use SQL `DECIMAL`; JavaScript money math uses fixed-scale `BigInt` helpers in `src/utils/money.js`.
- Request bodies are validated server-side with `zod`.
- SQL access goes through Knex query builders and transactions.
- Auth, password reset, deposit creation, and order creation have rate limiting.
- Every `/admin/*` route is protected by `auth`, `requireActive`, and `admin` middleware.
- Admin self-ban and last-active-admin lockout are rejected.
- Order prices are calculated on the server from `services.sell_price`; client-submitted prices are ignored.
- Production environment validation rejects missing or placeholder provider/JWT settings and requires `CORS_ORIGIN`.
- Production CORS allows only configured site origins.
- Wallet balance updates are centralized in `wallet.service.js` and covered by race-condition tests.