Skip to content

Releases: theworker02/VouchNet

VouchNet v0.9.2 — Security and persistent-session hardening

Choose a tag to compare

@theworker02 theworker02 released this 01 Oct 15:49

VouchNet v0.9.2 — Security and persistent-session hardening

Release date: 2026-10-01
Distribution: Source only — no binaries, installers, archives, or hosted artifacts are included.

Highlights

  • Per-request CSP nonces and strict dynamic script policy are now injected by Next.js Proxy.
  • Database and credential modules are marked server-only; browser build graphs cannot cross into
    the data access or provider-secret boundary.
  • Authorization-code OAuth uses strict form parsing, S256 PKCE validation, a five-minute code
    lifetime, exact redirect URI matching, and single-use database locks.
  • Sessions persist for active members for up to 30 days, while signing out after 24 hours of
    inactivity. A successful password sign-in rotates the current browser session.
  • An append-only, HMAC-IP security audit migration records selected authentication and OAuth client
    lifecycle events without retaining secrets or request bodies.
  • Drizzle ORM was updated to the patched ^0.45.2 range after the dependency audit identified a
    high-severity SQL identifier escaping advisory in earlier releases.

Verification

The source tree was checked with:

pnpm typecheck
pnpm lint
pnpm test
pnpm format:check
pnpm build
pnpm audit --audit-level=high

The final dependency audit reports no high-severity advisories. One moderate advisory remains and
should continue to be tracked through the new scheduled audit workflow.

Deployment requirements

  • Apply database migrations through 0023_session_idle_expiration.sql before deploying this
    release. 0022_security_audit_logs.sql creates the append-only audit trail.
  • Keep SESSION_SECRET at 32 or more characters; it salts the privacy-preserving audit IP HMAC.
  • Set a reachable production REDIS_URL. Rate-limited production mutations fail closed if Redis is
    unavailable.

Scope boundaries

This release improves the existing foundation. Full messaging, real-time notification delivery,
organization administration, complete job workflows, moderation operations, WebAuthn/passkeys,
and MCP gateway operations are still separate product work and are not represented as complete.

VouchNet v0.1.0

Choose a tag to compare

@theworker02 theworker02 released this 30 Sep 14:54

Changelog

All notable changes to VouchNet are documented here. This project follows
Semantic Versioning.

0.1.0 - 2026-09-30

Added

  • A VouchNet-branded Next.js professional-network foundation with responsive
    public, authenticated, profile, network, discovery, and settings surfaces.
  • Email/password authentication, verified-email architecture, secure server
    sessions, password-reset flow, and optional Resend delivery configuration.
  • PostgreSQL/Drizzle schema and migrations for identity, profiles, social
    graph, settings, media metadata, and high-signal content foundations.
  • Server-enforced actor and authorization boundaries, audit/trust contracts,
    environment validation, request logging, and database readiness reporting.
  • Docker-based local PostgreSQL and Redis development environment.
  • Netlify deployment configuration and production environment documentation.

Security

  • Local environment files are excluded from version control; the environment
    template contains placeholders only.
  • Protected API routes use server-side session and authorization checks.
  • The public automation model retains the human-approval requirement for
    protected social actions; MCP credentials do not impersonate human sessions.

Known limitations

  • This is an initial development release, not a production launch.
  • Hosted PostgreSQL, Redis, verified sending domain, and deployment-specific
    secrets must be configured before a public deployment.
  • Several product domains remain intentionally incomplete, including complete
    messaging, notifications, organizations, jobs, moderation, and MCP gateway
    operations. See docs/IMPLEMENTATION_MATRIX.md.