security: QA Council audit fixes

- Remove JWT secret fallbacks (fail on startup if missing)
- Hash refresh tokens with SHA-256 before DB storage
- Add Zod validation to bulk-approve, bulk-reject, update-user, copy-week
- Add global API rate limiting (100 req/15min per IP)
- Fix nginx X-XSS-Protection header (align with Helmet)
- Remove --accept-data-loss from Dockerfile CMD
- Create .gitignore to protect secrets from commits
- Secure .env file permissions (chmod 600)
This commit is contained in:
BizzleBot
2026-02-17 02:09:26 +00:00
parent 0739f87f73
commit 47c35c1e3a
9 changed files with 83 additions and 30 deletions
+1 -1
View File
@@ -55,4 +55,4 @@ HEALTHCHECK --interval=30s --timeout=5s --start-period=30s --retries=3 \
CMD node -e "fetch('http://localhost:3001/api/health').then(r=>{if(!r.ok)throw 1}).catch(()=>process.exit(1))"
# Start with migration and seed on first run
CMD ["sh", "-c", "npx prisma db push --accept-data-loss 2>/dev/null; node prisma/seed.js 2>/dev/null; node src/index.js"]
CMD ["sh", "-c", "npx prisma db push 2>/dev/null; node prisma/seed.js 2>/dev/null; node src/index.js"]