- Stateless JWT Tokens: Signed using HMAC-SHA256 with an environment secret (
JWT_SECRET). - Password Hashing: Bcrypt with a work factor of 10 rounds for all stored credentials.
- Header Authorization: Standard
Authorization: Bearer <token>required for all mutating endpoints (/api/orders,/api/positions/square-off,/api/account).
TradeForge enforces strict multi-tenant boundary checks across every state mutation:
- Order Ownership: When cancelling an order via
DELETE /api/orders/:id, the system explicitly queries the order'suser_idand rejects requests wherereq.user.id !== order.user_idwith HTTP 403 Forbidden (Unauthorized access to order). - Position Ownership: Position square-off queries only positions matching the authenticated
user_id. - Portfolio & Account Isolation: Balance queries and margin releases are strictly isolated by
user_id.
Automated in test/e2e-freeze-qa.ts:
// Verified Test: User A attempts to cancel User B's order
const unauthorizedCancel = await orderService.cancelOrder('usr_unauthorized_attacker', slmRes.order.id);
assert(!unauthorizedCancel.success);
assert(unauthorizedCancel.message === 'Unauthorized access to order');- Schema Validation: Explicit validation on all order parameters (Quantity, Price, Trigger Price, Product Type, Order Type).
- Environment Hygiene: No API keys, passwords, private keys, or tokens committed to source control.
.env.exampleprovides sanitized template values.