- Backend: Express.js + PostgreSQL/SQLite with LDAP/AD integration - Frontend: React 18 + Vite + TailwindCSS/DaisyUI - Security fixes applied (2026-07 + 2026-08): - LDAP injection prevention, CSRF protection, HttpOnly cookies - Session hashing (SHA-256), account lockout, rate limiting - Input validation (zod), file upload security, CSP/HSTS headers - V3: express-rate-limit updated (ip-address SSRF fix) - V4: postcss updated (nanoid DoS fix) - V5: Rate-limit on /health endpoint - V6: Session rotation on login (session fixation prevention) - V9: Task values array limit (DoS prevention) - V10: Frontend XSS audit completed - Docker: Multi-stage build, non-root user, PostgreSQL + backup service
49 lines
1.6 KiB
Plaintext
49 lines
1.6 KiB
Plaintext
# ============================================================
|
|
# Workflow Portal - Environment Configuration
|
|
# ============================================================
|
|
# Kopiere diese Datei zu .env und passe die Werte an.
|
|
# Alle Werte in <> müssen ausgefüllt werden.
|
|
# Werte mit Defaults können auskommentiert oder belassen werden.
|
|
# ============================================================
|
|
|
|
# ============ LDAP / Active Directory ============
|
|
LDAP_SERVER=PIDC02.seatle.intra
|
|
LDAP_PORT=636
|
|
LDAP_SEARCH_BASE=<z.B. DC=SEATLE,DC=INTRA>
|
|
LDAP_DOMAIN=SEATLE
|
|
LDAP_IGNORE_CERT_ERRORS=true
|
|
LDAP_BIND_USER=<z.B. svc_workflow@seatle.intra>
|
|
LDAP_BIND_PASSWORD=<LDAP-Service-Account-Passwort>
|
|
LDAP_SYNC_INTERVAL=300000
|
|
LDAP_FILTER=
|
|
LDAP_ATTRIBUTES=mail,displayName,memberOf,distinguishedName,sAMAccountName
|
|
LDAP_CREATE_OU=<z.B. OU=Users,OU=SEATLE,DC=SEATLE,DC=INTRA>
|
|
LDAP_UPN_SUFFIX=<z.B. seatle.intra>
|
|
|
|
# ============ Admin Account ============
|
|
ADMIN_EMAIL=admin@workflow.local
|
|
ADMIN_INIT_PASSWORD=<Admin-Initial-Passwort, min. 8 Zeichen mit Groß-/Kleinbuchstaben + Zahl>
|
|
|
|
# ============ Server ============
|
|
PORT=5000
|
|
NODE_ENV=production
|
|
CORS_ORIGIN=http://localhost:5000
|
|
|
|
# ============ PostgreSQL Database ============
|
|
POSTGRES_DB=workflow
|
|
POSTGRES_USER=workflow
|
|
POSTGRES_PASSWORD=<Sicheres Datenbank-Passwort>
|
|
# DATABASE_URL wird automatisch aus den Werten oben generiert:
|
|
# postgresql://workflow:<POSTGRES_PASSWORD>@db:5432/workflow
|
|
|
|
# ============ Security ============
|
|
SESSION_MAX_PER_USER=5
|
|
SESSION_TTL_HOURS=168
|
|
LOGIN_MAX_ATTEMPTS=5
|
|
LOGIN_LOCKOUT_MINUTES=15
|
|
BODY_LIMIT=1mb
|
|
UPLOAD_MAX_MB=10
|
|
|
|
# ============ DB Backup ============
|
|
BACKUP_INTERVAL_HOURS=6
|
|
BACKUP_RETENTION_DAYS=30 |