VouchNet v0.9.2 — Security and persistent-session hardening
VouchNet v0.9.2 — Security and persistent-session hardening
Release date: 2026-10-01
Distribution: Source only — no binaries, installers, archives, or hosted artifacts are included.
Highlights
- Per-request CSP nonces and strict dynamic script policy are now injected by Next.js Proxy.
- Database and credential modules are marked
server-only; browser build graphs cannot cross into
the data access or provider-secret boundary. - Authorization-code OAuth uses strict form parsing, S256 PKCE validation, a five-minute code
lifetime, exact redirect URI matching, and single-use database locks. - Sessions persist for active members for up to 30 days, while signing out after 24 hours of
inactivity. A successful password sign-in rotates the current browser session. - An append-only, HMAC-IP security audit migration records selected authentication and OAuth client
lifecycle events without retaining secrets or request bodies. - Drizzle ORM was updated to the patched
^0.45.2range after the dependency audit identified a
high-severity SQL identifier escaping advisory in earlier releases.
Verification
The source tree was checked with:
pnpm typecheck
pnpm lint
pnpm test
pnpm format:check
pnpm build
pnpm audit --audit-level=high
The final dependency audit reports no high-severity advisories. One moderate advisory remains and
should continue to be tracked through the new scheduled audit workflow.
Deployment requirements
- Apply database migrations through
0023_session_idle_expiration.sqlbefore deploying this
release.0022_security_audit_logs.sqlcreates the append-only audit trail. - Keep
SESSION_SECRETat 32 or more characters; it salts the privacy-preserving audit IP HMAC. - Set a reachable production
REDIS_URL. Rate-limited production mutations fail closed if Redis is
unavailable.
Scope boundaries
This release improves the existing foundation. Full messaging, real-time notification delivery,
organization administration, complete job workflows, moderation operations, WebAuthn/passkeys,
and MCP gateway operations are still separate product work and are not represented as complete.