Skip to content

Security: kunal-sonawane/StayScape

Security

SECURITY.md

Security Notes

  • Never commit .env or database/cloud credentials.
  • Use a unique SESSION_SECRET of at least 32 characters in production.
  • Keep MongoDB Atlas network access limited to the deployment environment where possible.
  • Direct image uploads are restricted by MIME type and a 5 MB per-file limit.
  • Authenticated state-changing forms require a CSRF token.
  • Sessions use random tokens stored as SHA-256/HMAC hashes in MongoDB; the raw token is only held by the browser cookie.
  • Passwords are hashed with Node.js crypto.scrypt and never stored in plain text.
  • Helmet sets security headers and a restrictive content security policy.
  • Rate limits protect the general app, authentication, uploads and geocoding endpoints.
  • User search text is escaped before being used in MongoDB regular expressions.
  • EJS output uses escaped interpolation for user-generated content.
  • Production errors hide internal details from the browser while returning a request ID for support.

There aren't any published security advisories