Harden web root, secrets and realtime auth
- .htaccess: refuse .git, .env, docker, nodejs, sdlc*, scripts, archives and app internals; security headers, HSTS over TLS, optional HTTPS redirect - uploads served through app/file.php to signed-in users only - Apache/PHP hardening config for the container (ServerTokens, expose_php) - least-privilege DB account and APP_SECRET_KEY via docker/php/provision.php; SMTP passwords re-encrypted with a random IV (secret_box.php) - Socket.IO rooms from a PHP-signed token; /emit and cron refuse empty secrets - escape notification text; CLI guards on build scripts; no fixed demo password
This commit is contained in:
@@ -44,6 +44,14 @@ if [ -z "$emit_secret" ]; then
|
||||
echo " generated: $emit_secret"
|
||||
fi
|
||||
|
||||
echo
|
||||
echo "== App secrets (generated) =="
|
||||
db_app_pass=$(openssl rand -hex 24)
|
||||
app_secret=$(openssl rand -hex 32)
|
||||
echo " DB_APP_PASSWORD and APP_SECRET_KEY generated (stored in $ENV_FILE only)."
|
||||
read -r -p "Serve over HTTPS (redirect HTTP → HTTPS)? Only answer y once TLS is set up [y/N]: " force_https
|
||||
case "$force_https" in [yY]*) force_https=true ;; *) force_https=false ;; esac
|
||||
|
||||
echo
|
||||
echo "== SMTP (outgoing mail) =="
|
||||
read -r -p "SMTP username (email address): " smtp_user
|
||||
@@ -57,6 +65,10 @@ SMTP_USERNAME=$smtp_user
|
||||
SMTP_PASSWORD=$smtp_pass
|
||||
OTP_REQUIRED=false
|
||||
HTTP_PORT=$http_port
|
||||
DB_APP_USER=wms_app
|
||||
DB_APP_PASSWORD=$db_app_pass
|
||||
APP_SECRET_KEY=$app_secret
|
||||
FORCE_HTTPS=$force_https
|
||||
EOF
|
||||
chmod 600 "$ENV_FILE"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user