- Backend: Express.js + PostgreSQL/SQLite with LDAP/AD integration - Frontend: React 18 + Vite + TailwindCSS/DaisyUI - Security fixes applied (2026-07 + 2026-08): - LDAP injection prevention, CSRF protection, HttpOnly cookies - Session hashing (SHA-256), account lockout, rate limiting - Input validation (zod), file upload security, CSP/HSTS headers - V3: express-rate-limit updated (ip-address SSRF fix) - V4: postcss updated (nanoid DoS fix) - V5: Rate-limit on /health endpoint - V6: Session rotation on login (session fixation prevention) - V9: Task values array limit (DoS prevention) - V10: Frontend XSS audit completed - Docker: Multi-stage build, non-root user, PostgreSQL + backup service
30 lines
908 B
Docker
30 lines
908 B
Docker
FROM node:20-alpine AS frontend-build
|
|
WORKDIR /app/frontend
|
|
COPY frontend/package*.json ./
|
|
RUN npm install
|
|
COPY frontend/ ./
|
|
RUN npm run build
|
|
|
|
FROM node:20-alpine
|
|
RUN apk add --no-cache python3 make g++ openssl wget su-exec
|
|
|
|
# Create non-root user (Punkt 6: Non-Root Container)
|
|
RUN addgroup -S appgroup && adduser -S appuser -G appgroup
|
|
|
|
WORKDIR /app
|
|
COPY backend/package*.json ./
|
|
RUN npm install
|
|
COPY backend/ ./
|
|
COPY --from=frontend-build /app/frontend/dist ./frontend/dist
|
|
|
|
# Create data directory
|
|
RUN mkdir -p /app/data/uploads
|
|
|
|
EXPOSE 5000
|
|
|
|
# Health check (Punkt 7: Docker Healthcheck)
|
|
HEALTHCHECK --interval=30s --timeout=5s --retries=3 --start-period=10s \
|
|
CMD wget -qO- http://localhost:5000/health || exit 1
|
|
|
|
# Entrypoint: fix permissions on mounted volumes, then run as non-root user
|
|
ENTRYPOINT ["sh", "-c", "chown -R appuser:appgroup /app/data 2>/dev/null; exec su-exec appuser node server.js"] |