DEV1.0: Initial commit - Workflow Portal with security fixes
- Backend: Express.js + PostgreSQL/SQLite with LDAP/AD integration - Frontend: React 18 + Vite + TailwindCSS/DaisyUI - Security fixes applied (2026-07 + 2026-08): - LDAP injection prevention, CSRF protection, HttpOnly cookies - Session hashing (SHA-256), account lockout, rate limiting - Input validation (zod), file upload security, CSP/HSTS headers - V3: express-rate-limit updated (ip-address SSRF fix) - V4: postcss updated (nanoid DoS fix) - V5: Rate-limit on /health endpoint - V6: Session rotation on login (session fixation prevention) - V9: Task values array limit (DoS prevention) - V10: Frontend XSS audit completed - Docker: Multi-stage build, non-root user, PostgreSQL + backup service
This commit is contained in:
33
.dockerignore
Normal file
33
.dockerignore
Normal file
@@ -0,0 +1,33 @@
|
||||
# ============ Dependencies ============
|
||||
**/node_modules
|
||||
**/package-lock.json
|
||||
|
||||
# ============ Build Artifacts ============
|
||||
**/dist
|
||||
frontend/dist
|
||||
|
||||
# ============ Data & Secrets ============
|
||||
**/data
|
||||
**/.env
|
||||
**/.env.*
|
||||
!.env.example
|
||||
|
||||
# ============ Git ============
|
||||
.git
|
||||
.gitignore
|
||||
|
||||
# ============ IDE ============
|
||||
.vscode
|
||||
.idea
|
||||
*.swp
|
||||
*.swo
|
||||
|
||||
# ============ Docker ============
|
||||
Dockerfile
|
||||
docker-compose.yml
|
||||
.dockerignore
|
||||
|
||||
# ============ Misc ============
|
||||
**/*.md
|
||||
**/.DS_Store
|
||||
**/Thumbs.db
|
||||
Reference in New Issue
Block a user