Harden web root, secrets and realtime auth

- .htaccess: refuse .git, .env, docker, nodejs, sdlc*, scripts, archives and
  app internals; security headers, HSTS over TLS, optional HTTPS redirect
- uploads served through app/file.php to signed-in users only
- Apache/PHP hardening config for the container (ServerTokens, expose_php)
- least-privilege DB account and APP_SECRET_KEY via docker/php/provision.php;
  SMTP passwords re-encrypted with a random IV (secret_box.php)
- Socket.IO rooms from a PHP-signed token; /emit and cron refuse empty secrets
- escape notification text; CLI guards on build scripts; no fixed demo password
This commit is contained in:
Thanakorn
2026-09-24 14:53:40 +07:00
parent e579dd596c
commit ae98dcdcdd
29 changed files with 525 additions and 42 deletions
+12
View File
@@ -44,6 +44,14 @@ if [ -z "$emit_secret" ]; then
echo " generated: $emit_secret"
fi
echo
echo "== App secrets (generated) =="
db_app_pass=$(openssl rand -hex 24)
app_secret=$(openssl rand -hex 32)
echo " DB_APP_PASSWORD and APP_SECRET_KEY generated (stored in $ENV_FILE only)."
read -r -p "Serve over HTTPS (redirect HTTP → HTTPS)? Only answer y once TLS is set up [y/N]: " force_https
case "$force_https" in [yY]*) force_https=true ;; *) force_https=false ;; esac
echo
echo "== SMTP (outgoing mail) =="
read -r -p "SMTP username (email address): " smtp_user
@@ -57,6 +65,10 @@ SMTP_USERNAME=$smtp_user
SMTP_PASSWORD=$smtp_pass
OTP_REQUIRED=false
HTTP_PORT=$http_port
DB_APP_USER=wms_app
DB_APP_PASSWORD=$db_app_pass
APP_SECRET_KEY=$app_secret
FORCE_HTTPS=$force_https
EOF
chmod 600 "$ENV_FILE"