Skip to content

Add security improvements: CSP config, body size limits, response caching, Dockerfile hardening - #366

Merged
EmmanuelOchaje merged 1 commit into
StellarTickets:mainfrom
AbelOsaretin:feat/security-improvements
Sep 26, 2026
Merged

EmmanuelOchaje merged 1 commit into
StellarTickets:mainfrom
AbelOsaretin:feat/security-improvements

Conversation

@AbelOsaretin

Copy link
Copy Markdown
Contributor

Closes #191, Closes #193, Closes #195, Closes #197

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Refactoring (no functional or behavioral changes)
  • Performance improvement
  • Documentation update
  • Build / CI configuration change
  • Dependency update
  • Other:

Summary

This PR addresses 4 security and reliability issues:

  1. Add security headers review and CSP for the API #191: Documents helmet security headers and adds CSP_DIRECTIVES env var for Content Security Policy configuration
  2. Add request body size limits #193: Adds JSON_BODY_LIMIT env var with configurable request body size limit (returns 413 on oversized payloads)
  3. Add response caching for public event listings #195: Adds ResponseCacheInterceptor for public event endpoints with configurable TTL cache and automatic invalidation on writes
  4. Add Dockerfile hardening: non-root user and multi-stage build #197: Hardens Dockerfile with non-root user, multi-stage build, and HEALTHCHECK

Motivation / Context

These changes improve the security posture and reliability of the backend API:

  • Security headers prevent common web vulnerabilities
  • Body size limits prevent DoS attacks via oversized payloads
  • Response caching reduces database load for read-heavy endpoints
  • Dockerfile hardening follows production best practices

Closes #191, Closes #193, Closes #195, Closes #197

@netlify

netlify Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for stellarticketsbackend ready!

Name Link
🔨 Latest commit 15f38e0
🔍 Latest deploy log https://app.netlify.com/projects/stellarticketsbackend/deploys/6ab7cf97e3061900082253e9
😎 Deploy Preview https://deploy-preview-366--stellarticketsbackend.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

…hing, Dockerfile hardening

- StellarTickets#191: Document helmet security headers and add CSP_DIRECTIVES env var
- StellarTickets#193: Add JSON_BODY_LIMIT env var with configurable request body size limit
- StellarTickets#195: Add ResponseCacheInterceptor for public event endpoints with TTL cache and invalidation on writes
- StellarTickets#197: Harden Dockerfile with non-root user and HEALTHCHECK

Closes StellarTickets#191, Closes StellarTickets#193, Closes StellarTickets#195, Closes StellarTickets#197
@AbelOsaretin
AbelOsaretin force-pushed the feat/security-improvements branch from ad48220 to 15f38e0 Compare September 26, 2026 13:58
@drips-wave

drips-wave Bot commented Sep 26, 2026

Copy link
Copy Markdown

@AbelOsaretin Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@EmmanuelOchaje
EmmanuelOchaje merged commit 88a69be into StellarTickets:main Sep 26, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants