mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-03 13:52:09 +03:00
FASE-01 — Security Hardening: - Remove hardcoded JWT_SECRET and API_KEY_SECRET fallbacks (fail-fast) - Create secretsValidator.js with enforceSecrets() at startup - Create inputSanitizer.js (prompt injection + PII detection) - Integrate sanitizer in chat.js handler pipeline - Add structured logging to silent catch blocks in proxy.js - Remove .passthrough() from Zod updateSettingsSchema - Remove insecure npm fs dependency - Update .env.example with generation commands FASE-02 — CI/CD & Tests: - Create ci.yml workflow (lint, build, test, coverage, e2e) - Fix test scripts (test now runs actual tests) - Add test:unit, test:security, test:coverage (c8), test:all - Add security rules to ESLint (no-eval, no-implied-eval, no-new-func) FASE-03 — Architecture: - Create settingsCache.js (eliminate self-fetch anti-pattern) - Create domain/types.js and domain/responses.js FASE-04 — Observability: - Create correlationId.js (AsyncLocalStorage tracing) - Create circuitBreaker.js (full state machine + registry) - Create requestTimeout.js (per-provider timeouts) FASE-05 — Code Quality: - Create structuredLogger.js (JSON/human-readable logging) FASE-06 — Documentation: - Update SECURITY.md with hardening practices - Create CONTRIBUTING.md with dev setup and PR checklist Tests: 52/52 pass (23 security + 15 observability + 14 integration)
66 lines
1.8 KiB
Markdown
66 lines
1.8 KiB
Markdown
# Security Policy
|
|
|
|
## Reporting Vulnerabilities
|
|
|
|
If you discover a security vulnerability in OmniRoute, please report it responsibly:
|
|
|
|
1. **DO NOT** open a public GitHub issue
|
|
2. Email: **security@omniroute.dev** (or use GitHub Security Advisories)
|
|
3. Include: description, reproduction steps, and potential impact
|
|
|
|
## Response Timeline
|
|
|
|
| Stage | Target |
|
|
| ------------------- | --------------------------- |
|
|
| Acknowledgment | 48 hours |
|
|
| Triage & Assessment | 5 business days |
|
|
| Patch Release | 14 business days (critical) |
|
|
|
|
## Supported Versions
|
|
|
|
| Version | Support Status |
|
|
| ------- | -------------- |
|
|
| 0.2.x | ✅ Active |
|
|
| < 0.2.0 | ❌ Unsupported |
|
|
|
|
## Security Best Practices
|
|
|
|
### Required Environment Variables
|
|
|
|
All secrets must be set before starting the server. The server will **fail fast** if they are missing or weak.
|
|
|
|
```bash
|
|
# Generate strong secrets:
|
|
JWT_SECRET=$(openssl rand -base64 48)
|
|
API_KEY_SECRET=$(openssl rand -hex 32)
|
|
STORAGE_ENCRYPTION_KEY=$(openssl rand -hex 32)
|
|
```
|
|
|
|
### Input Protection
|
|
|
|
OmniRoute includes built-in protection against:
|
|
|
|
- **Prompt injection** — Detects system override, role hijack, delimiter injection, and DAN/jailbreak patterns
|
|
- **PII leakage** — Optional detection and redaction of emails, CPF/CNPJ, credit cards, and phone numbers
|
|
|
|
Configure in `.env`:
|
|
|
|
```env
|
|
INPUT_SANITIZER_ENABLED=true
|
|
INPUT_SANITIZER_MODE=block # warn | block | redact
|
|
PII_REDACTION_ENABLED=true
|
|
```
|
|
|
|
### Docker Security
|
|
|
|
- Use non-root user in production
|
|
- Mount secrets as read-only volumes
|
|
- Never copy `.env` files into Docker images
|
|
- Use `.dockerignore` to exclude sensitive files
|
|
|
|
### Dependencies
|
|
|
|
- Run `npm audit` regularly
|
|
- Keep dependencies updated
|
|
- The project uses `husky` + `lint-staged` for pre-commit checks
|