Files
WhatIDo/.gitignore
T
dev 6844d659fc harden security and add public TLS scaffold
- require ADMIN_PASSWORD (no default), remove CORS
- close public DB port, move DB credentials to .env (DB_PASSWORD)
- fix HTML escaping, add helmet + sec headers (no CSP due to inline scripts)
- rate limit public routes by IP (express-rate-limit)
- validate restore data and confine file unlinking to uploads/
- block dangerous upload extensions, 30MB per-entry limit, SVG not served inline
- return 400 on unknown group_id in POST /api/entries
- add commented Caddy/Let's Encrypt reverse-proxy scaffold + Caddyfile.example
- update README
2026-09-07 11:27:04 +03:00

28 lines
309 B
Plaintext

# --- Environment / secrets ---
.env
.env.*
!.env.example
*.pem
*.key
*.crt
certs/
# --- Run-time data / uploads ---
uploads/
backups/
*.sql.gz
*.tar.gz
# --- Node ---
node_modules/
# --- Logs / tmp / OS ---
*.log
.tmp/
tmp/
.DS_Store
Thumbs.db
# --- Internal audit (not for commit) ---
SECURITY_AUDIT.md