Security: kunal-sonawane/StayScape
Security
Never commit .env or database/cloud credentials.
Use a unique SESSION_SECRET of at least 32 characters in production.
Keep MongoDB Atlas network access limited to the deployment environment where possible.
Direct image uploads are restricted by MIME type and a 5 MB per-file limit.
Authenticated state-changing forms require a CSRF token.
Sessions use random tokens stored as SHA-256/HMAC hashes in MongoDB; the raw token is only held by the browser cookie.
Passwords are hashed with Node.js crypto.scrypt and never stored in plain text.
Helmet sets security headers and a restrictive content security policy.
Rate limits protect the general app, authentication, uploads and geocoding endpoints.
User search text is escaped before being used in MongoDB regular expressions.
EJS output uses escaped interpolation for user-generated content.
Production errors hide internal details from the browser while returning a request ID for support.
There aren't any published security advisories
You can’t perform that action at this time.