fix(security): harden encryption key permissions, increase password minimum, remove sensitive logs (#323)

Self-heal encryption key file permissions to 0600 on startup. Increase
minimum password length from 6 to 8 characters per NIST SP 800-63B.
Remove console.log statements that exposed file paths, .env locations,
stack names, and admin usernames to stdout.
This commit is contained in:
Anso
2026-04-01 21:27:37 -04:00
committed by GitHub
parent 1c221508a2
commit f317a83814
11 changed files with 67 additions and 31 deletions
+2 -2
View File
@@ -175,8 +175,8 @@ export function SettingsModal({ isOpen, onClose }: SettingsModalProps) {
toast.error('New passwords do not match');
return;
}
if (authData.newPassword.length < 6) {
toast.error('New password must be at least 6 characters');
if (authData.newPassword.length < 8) {
toast.error('New password must be at least 8 characters');
return;
}
setIsSavingPassword(true);
+2 -2
View File
@@ -35,8 +35,8 @@ export function Setup({
return;
}
if (password.length < 6) {
setError('Password must be at least 6 characters');
if (password.length < 8) {
setError('Password must be at least 8 characters');
return;
}
@@ -78,8 +78,8 @@ export function UsersSection() {
toast.error('Password is required for new users.');
return;
}
if (formPassword && formPassword.length < 6) {
toast.error('Password must be at least 6 characters.');
if (formPassword && formPassword.length < 8) {
toast.error('Password must be at least 8 characters.');
return;
}
if (formPassword && formPassword !== formConfirmPassword) {
@@ -283,7 +283,7 @@ export function UsersSection() {
type="password"
value={formPassword}
onChange={(e) => setFormPassword(e.target.value)}
placeholder={editingUser ? 'Leave blank to keep' : 'min. 6 characters'}
placeholder={editingUser ? 'Leave blank to keep' : 'min. 8 characters'}
/>
</div>
<div className="space-y-2">