Skip to content

Security validations, Compose hardening, integration tests, and DX improvements - #1

Merged
smeinecke merged 1 commit into
mainfrom
security-and-dx-improvements
Jun 18, 2026
Merged

smeinecke merged 1 commit into
mainfrom
security-and-dx-improvements

Conversation

@smeinecke

Copy link
Copy Markdown

Summary

This PR addresses real gaps in configuration validation, deployment defaults, test coverage, and developer experience.

Security & correctness

  • Minimum SECRET length (32 chars) -- parseApiConfig now rejects one-character secrets that were silently accepted before.
  • ALGORITHM whitelist -- Only PBKDF2/SHA-256, PBKDF2/SHA-384, and PBKDF2/SHA-512 are accepted. Typos like SHA-256 now fail fast with a clear error instead of producing broken challenges.
  • Distinguishable /verify errors -- Returns 417 with { error: "invalid" } or { error: "replayed" } so clients can debug without guessing.

Production & deployment

  • Demo as opt-in Compose profile -- docker compose up --build now starts only the API. Use --profile demo to include the demo service.
  • Restart policy -- unless-stopped on both services for automatic recovery.
  • Resource limits -- 256M memory and 0.5 CPU caps to keep the scheduler friendly during traffic spikes.

Test coverage

  • Integration tests for api-app.ts -- New src/api-app.test.ts spins up the full Express app on an ephemeral port and exercises GET /, GET /challenge, and GET /verify (valid, invalid, missing, replayed) using Bun-native fetch.

Developer experience

  • bunfig.toml -- Test discovery is now explicit and shell-independent.
  • Request logging -- Lightweight METHOD path status duration middleware (disabled when NODE_ENV=test).

…improvements

- Enforce minimum SECRET length (32 chars) in parseApiConfig
- Validate ALGORITHM against PBKDF2 whitelist (SHA-256/384/512)
- Return distinguishable JSON error bodies from /verify:
  { error: "invalid" } vs { error: "replayed" }
- Make demo service opt-in via Compose profile (--profile demo)
- Add restart: unless-stopped and resource limits to compose.yaml
- Add HTTP-level integration tests for api-app.ts (native fetch)
- Move test glob to bunfig.toml for shell-independent discovery
- Add lightweight request logging middleware (disabled in test)
@smeinecke
smeinecke merged commit 5c57dab into main Jun 18, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant