| Version | Supported |
|---|---|
| 1.0.x | ✅ |
Please do not report security vulnerabilities through public GitHub issues.
If you discover a security issue, please report it privately:
- Open a GitHub Security Advisory, or
- Email the maintainer via GitHub profile contact
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We aim to respond within 72 hours and will keep you informed of the resolution timeline.
- Change all default secrets in
.env:JWT_SECRET,JWT_REFRESH_SECRET,CSRF_SECRET
- Change default admin password immediately after first login
- Disable registration in Settings unless needed
- Use HTTPS behind a reverse proxy (nginx, Traefik, Caddy)
- Restrict MongoDB — do not expose port 27017 publicly
- Set strong
CORS_ORIGINto your actual frontend domain - Review rate limit settings in Settings page and environment variables
- Enable log retention and periodically review audit logs
| Field | Default |
|---|---|
| Login | admin |
| Password | Admin123! |
These are seeded on first run. Never use in production without changing.
- Passwords hashed with bcrypt (cost factor 12)
- JWT access tokens (short-lived) + refresh tokens (long-lived)
- Failed login lockout configurable per IP
- RBAC enforced on all management endpoints
- Dynamic endpoints created as
publicare accessible without authentication - CSRF protection is available via
/api/csrf-tokenbut cookie-based flows require HTTPS in production - JWT expiry from Settings UI is stored in DB; server restart may still use env defaults for token generation until fully dynamic
Security fixes will be released as patch versions (e.g. 1.0.1) and documented in CHANGELOG.md.