2.3 KiB
2.3 KiB
Security review
Review date: 2026-08-01
Scope
Next.js portal and APIs, Discord bot, PostgreSQL persistence, Keycloak admin authentication, and the Velocity admission plugin.
Automated checks
- Semgrep
auto: 0 findings npm audit: 0 known vulnerabilities after dependency overrides- TypeScript, ESLint, unit tests, Next.js production build: passing
- Velocity Java tests and shaded plugin build: passing
Implemented controls
- Discord login and session tokens use cryptographically secure randomness and are stored only as SHA-256 hashes.
- Login links expire after ten minutes, are single use, and are rate limited per Discord user with a PostgreSQL advisory lock.
- Session cookies are
httpOnly,sameSite=lax, path-scoped, and secure in production. - Admin access uses Keycloak OIDC and a required role.
- User mutations verify ownership server-side.
- Mojang lookup is server-side and targets a fixed host, avoiding client-forged validation and SSRF.
- Velocity credentials are high-entropy bearer tokens stored only as hashes.
- Velocity requests have a 45-second clock window and database-unique request IDs for cross-instance replay prevention.
- Velocity and its API fail closed.
- ORM-parameterized queries are used throughout.
- CSP, clickjacking, MIME-sniffing, referrer, and browser-permission headers are configured.
- Forwarded IP headers are ignored unless
TRUST_PROXY=trueis explicitly configured. - Secrets are excluded from logs and repository configuration.
Outstanding production requirements
- Select and implement a VPN/proxy intelligence provider before enabling VPN-based account-addition blocking. The current classification is explicitly
unknown. - Define and automate retention for exact IP addresses and audit events.
- Add monitoring and alerts for repeated login denials, plugin authentication failures, and Discord API failures.
- Use HTTPS for the public application and Velocity API URL. Protect the Velocity configuration file because it contains the one-time-displayed API token.
- Restrict database credentials so normal application roles cannot update or delete historical event rows outside approved application paths.
- Validate migrations in staging before production. Local migration application was unavailable during development because the Docker daemon was not running.