Add HTTP service hardening policy for 1.0 releases (#17)
check / check (push) Successful in 8s
check / check (push) Successful in 8s
Closes #16 Adds a comprehensive HTTP/web service security hardening policy to `REPO_POLICIES.md` that must be satisfied before tagging 1.0. The policy covers all items sneak specified (without limitation): **Security headers** — HSTS (min 1 year, includeSubDomains), CSP (restrictive `default-src 'self'` baseline), X-Frame-Options / frame-ancestors, X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy. **Request/response limits** — max request body size on all endpoints, max response size for paginated APIs, ReadTimeout + ReadHeaderTimeout (slowloris defense), WriteTimeout, IdleTimeout, per-handler execution time limits. **Authentication & session security** — rate limiting on password-based auth (API keys exempt as high-entropy), CSRF tokens on state-mutating forms (header-auth APIs exempt), bcrypt/scrypt/argon2 for passwords, session cookies with HttpOnly + Secure + SameSite. **Reverse proxy awareness** — true client IP detection via X-Forwarded-For/X-Real-IP with trusted proxy allowlist (never trust unconditionally). **CORS** — explicit origin allowlist for authenticated endpoints; wildcard only for public unauthenticated read-only APIs. **Error handling** — no leaking stack traces, SQL queries, file paths, or implementation details to clients. **TLS** — HSTS and secure cookie flags required regardless of whether the service terminates TLS directly or sits behind a reverse proxy. The policy is explicitly non-exhaustive (defense-in-depth: "when in doubt, harden"). Also adds corresponding checklist sections to `EXISTING_REPO_CHECKLIST.md` and `NEW_REPO_CHECKLIST.md` so that HTTP hardening is verified during repo setup and 1.0 preparation. Co-authored-by: user <user@Mac.lan guest wan> Co-authored-by: clawbot <clawbot@eeqj.de> Reviewed-on: #17 Co-authored-by: clawbot <clawbot@noreply.example.org> Co-committed-by: clawbot <clawbot@noreply.example.org>
This commit was merged in pull request #17.
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
---
|
||||
title: Existing Repo Checklist
|
||||
last_modified: 2026-02-22
|
||||
last_modified: 2026-03-10
|
||||
---
|
||||
|
||||
Use this checklist when beginning work in a repo that may not yet conform to our
|
||||
@@ -78,6 +78,22 @@ with your task.
|
||||
`internal/`, `static/`, etc.)
|
||||
- [ ] Go migrations in `internal/db/migrations/` and embedded in binary
|
||||
|
||||
# HTTP Service Hardening (if targeting 1.0 and the repo is an HTTP/web service)
|
||||
|
||||
- [ ] Security headers set on all responses (HSTS, CSP, X-Frame-Options,
|
||||
X-Content-Type-Options, Referrer-Policy, Permissions-Policy)
|
||||
- [ ] Request body size limits enforced on all endpoints
|
||||
- [ ] Read/write/idle timeouts configured on the HTTP server (slowloris defense)
|
||||
- [ ] Per-handler execution time limits in place
|
||||
- [ ] Password-based auth endpoints are rate-limited
|
||||
- [ ] CSRF tokens on all state-mutating HTML forms
|
||||
- [ ] Passwords hashed with bcrypt, scrypt, or argon2
|
||||
- [ ] Session cookies use HttpOnly, Secure, and SameSite attributes
|
||||
- [ ] True client IP correctly detected behind reverse proxy (trusted proxy
|
||||
allowlist configured)
|
||||
- [ ] CORS restricted to explicit origin allowlist for authenticated endpoints
|
||||
- [ ] Error responses do not leak stack traces, SQL queries, or internal paths
|
||||
|
||||
# Final
|
||||
|
||||
- [ ] `make check` passes
|
||||
|
||||
Reference in New Issue
Block a user