Lb1/docs/SECURITY.md

1.3 KiB

🛡️ Luxe Platform - Enterprise Security Model & Audit Checklist

Security Mitigations & Standards

1. OWASP Top 10 Protections

  • SQL Injection: Handled natively by Prisma ORM prepared statements and parameterized queries.
  • Cross-Site Scripting (XSS): Handled by @fastify/helmet setting strict HTTP security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options).
  • Cross-Site Request Forgery (CSRF): Refresh tokens are stored in HttpOnly, SameSite=Strict, Secure cookies.
  • Brute Force Protection: Rate limiting enforced at 100 requests / 15 minutes per IP via @fastify/rate-limit, plus progressive account login lockouts.

2. Password & Encryption Standards

  • Password Hashing: Argon2id with 64MB memory cost, 3 iterations, and 4 degree parallelism.
  • Tokens: JWT (ES2022 / RS256 or HS256) short-lived access tokens (15m) with refresh token rotation (7d).

3. Dynamic Policy RBAC

  • Role-based and Permission-based dynamic policy evaluation on every sensitive endpoint.
  • Database-driven permissions preventing hardcoded authorization checks.

4. Audit Logging

  • Every sensitive action (Status updates, User suspensions, Verification approvals, Balance adjustments) records an immutable AuditLog entry tagged with IP, User Agent, Timestamp, and Admin ID.