Skip to content

VouchNet v0.9.2 — Security and persistent-session hardening

Choose a tag to compare

@theworker02 theworker02 released this 01 Oct 15:49
· 14 commits to master since this release

VouchNet v0.9.2 — Security and persistent-session hardening

Release date: 2026-10-01
Distribution: Source only — no binaries, installers, archives, or hosted artifacts are included.

Highlights

  • Per-request CSP nonces and strict dynamic script policy are now injected by Next.js Proxy.
  • Database and credential modules are marked server-only; browser build graphs cannot cross into
    the data access or provider-secret boundary.
  • Authorization-code OAuth uses strict form parsing, S256 PKCE validation, a five-minute code
    lifetime, exact redirect URI matching, and single-use database locks.
  • Sessions persist for active members for up to 30 days, while signing out after 24 hours of
    inactivity. A successful password sign-in rotates the current browser session.
  • An append-only, HMAC-IP security audit migration records selected authentication and OAuth client
    lifecycle events without retaining secrets or request bodies.
  • Drizzle ORM was updated to the patched ^0.45.2 range after the dependency audit identified a
    high-severity SQL identifier escaping advisory in earlier releases.

Verification

The source tree was checked with:

pnpm typecheck
pnpm lint
pnpm test
pnpm format:check
pnpm build
pnpm audit --audit-level=high

The final dependency audit reports no high-severity advisories. One moderate advisory remains and
should continue to be tracked through the new scheduled audit workflow.

Deployment requirements

  • Apply database migrations through 0023_session_idle_expiration.sql before deploying this
    release. 0022_security_audit_logs.sql creates the append-only audit trail.
  • Keep SESSION_SECRET at 32 or more characters; it salts the privacy-preserving audit IP HMAC.
  • Set a reachable production REDIS_URL. Rate-limited production mutations fail closed if Redis is
    unavailable.

Scope boundaries

This release improves the existing foundation. Full messaging, real-time notification delivery,
organization administration, complete job workflows, moderation operations, WebAuthn/passkeys,
and MCP gateway operations are still separate product work and are not represented as complete.