fix(cms): implement v2 security and stability review findings
CI Pipeline with Test Management / 🧪 Run Tests & Generate Reports (push) Waiting to run
CI Pipeline with Test Management / 🐳 Docker Integration Tests (push) Blocked by required conditions
CI Pipeline with Test Management / 🏗️ Build Docker Image (push) Blocked by required conditions
CI Pipeline with Test Management / 📊 Generate Test Summary (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / 🧪 Run Tests & Generate Reports (push) Waiting to run
Test Reporting & Gherkin Analysis / 📊 Analyze Test Coverage (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / 🔄 Sync with Linear (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / ⚡ Performance Monitoring (push) Blocked by required conditions
CI Pipeline with Test Management / 🧪 Run Tests & Generate Reports (push) Waiting to run
CI Pipeline with Test Management / 🐳 Docker Integration Tests (push) Blocked by required conditions
CI Pipeline with Test Management / 🏗️ Build Docker Image (push) Blocked by required conditions
CI Pipeline with Test Management / 📊 Generate Test Summary (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / 🧪 Run Tests & Generate Reports (push) Waiting to run
Test Reporting & Gherkin Analysis / 📊 Analyze Test Coverage (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / 🔄 Sync with Linear (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / ⚡ Performance Monitoring (push) Blocked by required conditions
Resolves: - CSRF false positive checked (global POST protection) - Publish mutex to prevent git lock / double deploy - Basic Auth rate limit checked before credential evaluation - Memory leak in rate limiter (added GC interval) - XSS in Toast messages - XSS in data-path attribute - CI healthcheck port mismatch (3000 -> 8080) - Added security headers (X-Frame-Options, X-Content-Type-Options)
This commit is contained in:
@@ -10,7 +10,7 @@ services:
|
||||
- DEPLOY_VERSION=${DEPLOY_VERSION:-unversioned}
|
||||
container_name: mozdit-app-prod
|
||||
ports:
|
||||
- "8080:3000" # Host port 8080 elkerüli a lokális npm dev (3000) összeakadást
|
||||
- "127.0.0.1:8080:3000" # Belső port — csak nginx reverse proxy-n keresztül elérhető
|
||||
environment:
|
||||
- NODE_ENV=production
|
||||
# No fallback for MONGODB_URI: with root auth enabled on the Mongo container an
|
||||
@@ -37,7 +37,7 @@ services:
|
||||
image: mongo:7.0
|
||||
container_name: mozdit-mongodb-prod
|
||||
ports:
|
||||
- "27018:27017" # Host port 27018 elkerüli az összeakadást a lokális Mongo-val
|
||||
- "127.0.0.1:27018:27017" # Belső port, nem publikus az internet felé
|
||||
environment:
|
||||
- MONGO_INITDB_ROOT_USERNAME=${MONGO_ROOT_USER:-admin}
|
||||
# No weak default password: a missing value must fail the container loudly.
|
||||
|
||||
Reference in New Issue
Block a user