mirror of
https://github.com/R0m1k3/Socialflow.git
synced 2026-10-11 17:26:45 +02:00
feat(security): implement security fixes - Add AES-256-GCM encryption for Facebook/Instagram tokens - Add helmet for HTTP security headers - Add rate limiting (5 login attempts, 100 req/15min) - Add file upload validation (50MB max, MIME type whitelist) - Secure SQL console endpoint (disabled in production) - Enforce SESSION_SECRET in production
This commit is contained in:
1 parent
c3660f811b
commit
633875e8ec
7 files changed
+917
-450
No files matched your search
@@ -16,6 +16,10 @@ APP_URL=http://localhost:5555
|
||||
# Clé secrète pour les sessions (CHANGEZ CETTE VALEUR)
|
||||
SESSION_SECRET=your-secret-key-change-me-to-random-string
|
||||
|
||||
# Clé de chiffrement pour les tokens Facebook/Instagram (OBLIGATOIRE en production)
|
||||
# Générer avec: openssl rand -hex 32
|
||||
ENCRYPTION_KEY=your-32-byte-hex-key-here
|
||||
|
||||
# Clé API OpenRouter pour la génération de texte IA
|
||||
# Obtenez votre clé sur https://openrouter.ai/
|
||||
OPENROUTER_API_KEY=your-openrouter-api-key-here
|
||||
|
||||
Reference in new issue
Block a user