Skip to content

fix: security audit — resolve critical vulnerabilities and harden inf… - #63

Open
dumepaepp wants to merge 2 commits into
GizzZmo:mainfrom
dumepaepp:fix/security-audit-and-hardening
Open

fix: security audit — resolve critical vulnerabilities and harden inf…#63
dumepaepp wants to merge 2 commits into
GizzZmo:mainfrom
dumepaepp:fix/security-audit-and-hardening

Conversation

@dumepaepp

Copy link
Copy Markdown

…rastructure

Critical fixes:

  • Fix role self-escalation: users could register as admin via POST body
  • Fix Sequelize syntax bug (MongoDB syntax used — queries silently broken)
  • Enforce JWT_SECRET validation at startup (reject weak/missing secrets)
  • Fix XSS sanitization bypass (only stripped <script> tags, not img/svg/event handlers)

High fixes:

  • Fix IP whitelist memory leak (mutable array pushed on every request)
  • Add JWT token management to frontend (auto-refresh, 401 handling)
  • Fix graceful shutdown to close MongoDB, RabbitMQ, Redis connections
  • Remove duplicate signal handlers from app.js (lifecycle in server.js)
  • Add RabbitMQ reconnection with exponential backoff and poison pill handling

Medium fixes:

  • Remove double module.exports in auth middleware
  • Dockerfiles: npm ci, non-root user, healthchecks
  • docker-compose: env-var credentials with RequiredVar guards
  • Add .gitignore, .env.example, frontend/nginx.conf
  • Add comprehensive REVIEW.md with remaining recommendations

…rastructure

Critical fixes:
- Fix role self-escalation: users could register as admin via POST body
- Fix Sequelize  syntax bug (MongoDB syntax used — queries silently broken)
- Enforce JWT_SECRET validation at startup (reject weak/missing secrets)
- Fix XSS sanitization bypass (only stripped <script> tags, not img/svg/event handlers)

High fixes:
- Fix IP whitelist memory leak (mutable array pushed on every request)
- Add JWT token management to frontend (auto-refresh, 401 handling)
- Fix graceful shutdown to close MongoDB, RabbitMQ, Redis connections
- Remove duplicate signal handlers from app.js (lifecycle in server.js)
- Add RabbitMQ reconnection with exponential backoff and poison pill handling

Medium fixes:
- Remove double module.exports in auth middleware
- Dockerfiles: npm ci, non-root user, healthchecks
- docker-compose: env-var credentials with RequiredVar guards
- Add .gitignore, .env.example, frontend/nginx.conf
- Add comprehensive REVIEW.md with remaining recommendations
@gitguardian

gitguardian Bot commented Aug 14, 2026

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

Since your pull request originates from a forked repository, GitGuardian is not able to associate the secrets uncovered with secret incidents on your GitGuardian dashboard.
Skipping this check run and merging your pull request will create secret incidents on your GitGuardian dashboard.

🔎 Detected hardcoded secret in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
- - Generic Password 1e055fa docker-compose.yml View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

The PostgreSQL init.sql was missing several columns that the Sequelize
User model defines (mfaTempSecret, mfaBackupCodes, mfaRecoveryCode,
knownIPs, knownDevices, typicalLoginHours, loginSessions, permissions).
This caused 'column does not exist' errors on registration.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant