security: QA Council audit fixes

- Remove JWT secret fallbacks (fail on startup if missing)
- Hash refresh tokens with SHA-256 before DB storage
- Add Zod validation to bulk-approve, bulk-reject, update-user, copy-week
- Add global API rate limiting (100 req/15min per IP)
- Fix nginx X-XSS-Protection header (align with Helmet)
- Remove --accept-data-loss from Dockerfile CMD
- Create .gitignore to protect secrets from commits
- Secure .env file permissions (chmod 600)
This commit is contained in:
BizzleBot
2026-02-17 02:09:26 +00:00
parent 0739f87f73
commit 47c35c1e3a
9 changed files with 83 additions and 30 deletions
+15
View File
@@ -0,0 +1,15 @@
# Secrets
.env
.env.local
.env.*.local
docker/.env
*.pem
*.key
# Dependencies
node_modules/
# Runtime
*.log
.DS_Store
dist/