Skip to content

[Admin] Audit Feedback #174

@karntrehan

Description

@karntrehan

Todo:

  • [H] Rate limit - Implement on Hasura and handle error on FE. - @amit-s19 @choxx #
  • [H] Password encryption - User service already has this out of the box. We need to implement the same on admin. @amit-s19 @choxx #
  • [M] Fix CORS Issue - @amit-s19 @choxx #
  • [L] Remove server version - @choxx #
  • [L] Account Lockout - Lock account / rate limit invalid login attempts. - @amit-s19 @choxx #
  • [M] Improper Authorization - Sending entire token would need to fix this. @amit-s19

To Evaluate:

  • [H] HTTP Method - Options, Put, Patch, Delete would need to be removed? - @amit-s19 @choxx #
  • [M] Etag exposure by FA - @choxx #
  • [L] Http Security Headers - Consider adding security headers. - @choxx #

Not needed:

  • Session Timeout - This is not a valid usecase for us.
  • Forgot Password - This is not a valid usecase for us.
  • CAPTCHA - This is not a valid usecase for us.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions