Releases: theworker02/VouchNet
Releases · theworker02/VouchNet
Release list
VouchNet v0.9.2 — Security and persistent-session hardening
VouchNet v0.9.2 — Security and persistent-session hardening
Release date: 2026-10-01
Distribution: Source only — no binaries, installers, archives, or hosted artifacts are included.
Highlights
- Per-request CSP nonces and strict dynamic script policy are now injected by Next.js Proxy.
- Database and credential modules are marked
server-only; browser build graphs cannot cross into
the data access or provider-secret boundary. - Authorization-code OAuth uses strict form parsing, S256 PKCE validation, a five-minute code
lifetime, exact redirect URI matching, and single-use database locks. - Sessions persist for active members for up to 30 days, while signing out after 24 hours of
inactivity. A successful password sign-in rotates the current browser session. - An append-only, HMAC-IP security audit migration records selected authentication and OAuth client
lifecycle events without retaining secrets or request bodies. - Drizzle ORM was updated to the patched
^0.45.2range after the dependency audit identified a
high-severity SQL identifier escaping advisory in earlier releases.
Verification
The source tree was checked with:
pnpm typecheck
pnpm lint
pnpm test
pnpm format:check
pnpm build
pnpm audit --audit-level=high
The final dependency audit reports no high-severity advisories. One moderate advisory remains and
should continue to be tracked through the new scheduled audit workflow.
Deployment requirements
- Apply database migrations through
0023_session_idle_expiration.sqlbefore deploying this
release.0022_security_audit_logs.sqlcreates the append-only audit trail. - Keep
SESSION_SECRETat 32 or more characters; it salts the privacy-preserving audit IP HMAC. - Set a reachable production
REDIS_URL. Rate-limited production mutations fail closed if Redis is
unavailable.
Scope boundaries
This release improves the existing foundation. Full messaging, real-time notification delivery,
organization administration, complete job workflows, moderation operations, WebAuthn/passkeys,
and MCP gateway operations are still separate product work and are not represented as complete.
VouchNet v0.1.0
Changelog
All notable changes to VouchNet are documented here. This project follows
Semantic Versioning.
0.1.0 - 2026-09-30
Added
- A VouchNet-branded Next.js professional-network foundation with responsive
public, authenticated, profile, network, discovery, and settings surfaces. - Email/password authentication, verified-email architecture, secure server
sessions, password-reset flow, and optional Resend delivery configuration. - PostgreSQL/Drizzle schema and migrations for identity, profiles, social
graph, settings, media metadata, and high-signal content foundations. - Server-enforced actor and authorization boundaries, audit/trust contracts,
environment validation, request logging, and database readiness reporting. - Docker-based local PostgreSQL and Redis development environment.
- Netlify deployment configuration and production environment documentation.
Security
- Local environment files are excluded from version control; the environment
template contains placeholders only. - Protected API routes use server-side session and authorization checks.
- The public automation model retains the human-approval requirement for
protected social actions; MCP credentials do not impersonate human sessions.
Known limitations
- This is an initial development release, not a production launch.
- Hosted PostgreSQL, Redis, verified sending domain, and deployment-specific
secrets must be configured before a public deployment. - Several product domains remain intentionally incomplete, including complete
messaging, notifications, organizations, jobs, moderation, and MCP gateway
operations. Seedocs/IMPLEMENTATION_MATRIX.md.