CDP 35948520/Checkliste Node.js: 4 Web App Security Checks #34
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Quelle
samples/CDP/checklists/nodejs.xlsxCheckliste (4 Checks)
Phase: Build
Configuration
✅ Container-User
nextjs(uid=1001), non-root (Dockerfile.prod:87).✅ Äquivalent: eigenes Rate-Limit-Middleware (
packages/api/src/middleware/rate-limit.ts) — 100/15min API, 5/15min Auth.✅ Äquivalent: Next.js Security-Headers via
next.config.ts(HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy).✅ Äquivalent: Auth.js CSRF-Token (
authjs.csrf-tokenCookie, sieheauth.config.ts:35) + SameSite=Strict auf allen Cookies.Review-Ergebnis
Detail-Analyse aller 4 Checks aus
samples/CDP/checklists/nodejs.xlsxgegen CapaKraken-Code unddocs/acn-security-compliance-status.md.Empfehlung:
Alle Checks abgedeckt. Ticket kann nach Owner-Review geschlossen werden.
Abschluss
Alle 4 Checks aus
samples/CDP/checklists/nodejs.xlsxsind erfüllt:rate-limiter-flexible) ✅next.config.tsstattHelmet) ✅SameSite=Strictstattcsurf) ✅Ticket wird geschlossen.