- require ADMIN_PASSWORD (no default), remove CORS - close public DB port, move DB credentials to .env (DB_PASSWORD) - fix HTML escaping, add helmet + sec headers (no CSP due to inline scripts) - rate limit public routes by IP (express-rate-limit) - validate restore data and confine file unlinking to uploads/ - block dangerous upload extensions, 30MB per-entry limit, SVG not served inline - return 400 on unknown group_id in POST /api/entries - add commented Caddy/Let's Encrypt reverse-proxy scaffold + Caddyfile.example - update README
28 lines
309 B
Plaintext
28 lines
309 B
Plaintext
# --- Environment / secrets ---
|
|
.env
|
|
.env.*
|
|
!.env.example
|
|
*.pem
|
|
*.key
|
|
*.crt
|
|
certs/
|
|
|
|
# --- Run-time data / uploads ---
|
|
uploads/
|
|
backups/
|
|
*.sql.gz
|
|
*.tar.gz
|
|
|
|
# --- Node ---
|
|
node_modules/
|
|
|
|
# --- Logs / tmp / OS ---
|
|
*.log
|
|
.tmp/
|
|
tmp/
|
|
.DS_Store
|
|
Thumbs.db
|
|
|
|
# --- Internal audit (not for commit) ---
|
|
SECURITY_AUDIT.md
|