feat(security): implement security fixes - Add AES-256-GCM encryption for Facebook/Instagram tokens - Add helmet for HTTP security headers - Add rate limiting (5 login attempts, 100 req/15min) - Add file upload validation (50MB max, MIME type whitelist) - Secure SQL console endpoint (disabled in production) - Enforce SESSION_SECRET in production

This commit is contained in:
Michael committed 2026-01-07 14:57:36 +01:00
1 parent c3660f811b
commit 633875e8ec
7 files changed
+917 -450

No files matched your search

+4
View File
@@ -16,6 +16,10 @@ APP_URL=http://localhost:5555
# Clé secrète pour les sessions (CHANGEZ CETTE VALEUR)
SESSION_SECRET=your-secret-key-change-me-to-random-string
# Clé de chiffrement pour les tokens Facebook/Instagram (OBLIGATOIRE en production)
# Générer avec: openssl rand -hex 32
ENCRYPTION_KEY=your-32-byte-hex-key-here
# Clé API OpenRouter pour la génération de texte IA
# Obtenez votre clé sur https://openrouter.ai/
OPENROUTER_API_KEY=your-openrouter-api-key-here