Skip to content

v1.0.9 — Security Hardening and Shared Rate Limiting

Choose a tag to compare

@feskolech feskolech released this 22 Mar 10:25
· 8 commits to main since this release

This release focuses on security hardening, safer production defaults, and more resilient request throttling.

Highlights

  • Added stronger production startup checks for insecure default or weak secrets
  • Introduced optional FORCE_HTTPS and safer production behavior around transport security
  • Disabled OpenAPI exposure by default in production unless explicitly enabled
  • Removed legacy Telegram OAuth polling token support via query string
  • Added Cache-Control: no-store for API responses handling sensitive data
  • Strengthened sensitive-action protection for destructive account and admin operations
  • Added Redis-backed shared rate limiting with in-memory fallback for local and degraded scenarios
  • Hardened Telegram bot token handling
  • Expanded CI with secret scanning and dependency audit jobs
  • Added regression tests for security-sensitive flows

Operational Notes

  • Replace placeholder values for JWT_SECRET, COOKIE_SECRET, and ENCRYPTION_KEY before production deploy
  • If needed, generate secrets with openssl rand -hex 32
  • OPENAPI_ENABLED should remain disabled in production unless explicitly required
  • Docker Compose now defaults to Redis-backed rate limiting via the internal Redis service

Versioning

This is a patch release under the current versioning policy because it improves security and deployment safety without introducing intended breaking changes.

Full Changelog: v1.0.8...v1.0.9