15 lines
1.0 KiB
Markdown
15 lines
1.0 KiB
Markdown
# Security Checklist
|
|
|
|
- Passwords are hashed with `bcryptjs` before storage.
|
|
- Provider API credentials are read only from environment variables and are never returned by public APIs.
|
|
- Money columns use SQL `DECIMAL`; JavaScript money math uses fixed-scale `BigInt` helpers in `src/utils/money.js`.
|
|
- Request bodies are validated server-side with `zod`.
|
|
- SQL access goes through Knex query builders and transactions.
|
|
- Auth, password reset, deposit creation, and order creation have rate limiting.
|
|
- Every `/admin/*` route is protected by `auth`, `requireActive`, and `admin` middleware.
|
|
- Admin self-ban and last-active-admin lockout are rejected.
|
|
- Order prices are calculated on the server from `services.sell_price`; client-submitted prices are ignored.
|
|
- Production environment validation rejects missing or placeholder provider/JWT settings and requires `CORS_ORIGIN`.
|
|
- Production CORS allows only configured site origins.
|
|
- Wallet balance updates are centralized in `wallet.service.js` and covered by race-condition tests.
|