fix(security): audit batch A — validation, rate limiting, sessions #20

Merged
cesnimda merged 1 commits from fix/audit-critical-backend into develop 2026-07-02 03:22:17 +02:00

1 Commits

Author SHA1 Message Date
cesnimda 9480033373 fix(security): audit remediation batch A — validation, rate limiting, sessions
CI / backend (pull_request) Successful in 53s
CI / frontend (pull_request) Successful in 15s
Security / secrets (pull_request) Successful in 3s
Security / dependencies (pull_request) Successful in 55s
Implements AUDIT_REPORT.md items H-1, H-2, M-1, M-4, M-6, L-3:
- H-1: enable FluentValidation auto-validation — the registered validators (incl.
  Confirmed-required-for-destructive) now actually execute; invalid DTOs 400 at the
  boundary instead of reaching services.
- H-2: ASP.NET Core rate limiting — global per-user/per-IP fixed window (300/min
  default) + stricter 'auth' (10/min) and 'expensive' (20/min: export, unsubscribe,
  AI) policies; config-driven; 429 with no queue.
- M-1: absolute session lifetime (30d default) — an issued-at stamp set at sign-in
  and checked in OnValidatePrincipal, so a stolen cookie can no longer slide-renew
  forever. Pre-existing sessions re-login once.
- M-4: remove the guessable default DB password from appsettings; startup fails fast
  with a clear message when the connection string has no password (compose/staging
  inject the real one).
- M-6: matching tenant query filter on EmailLabel (via Email navigation) — clears
  the long-standing EF boot warning and closes the join-row leak window.
- L-3: SMTP skip-notice logging downgraded to Debug (recipient address is PII-ish).

Tests: 6 new (400-on-invalid x2, 429 auth rate limit via a test auth scheme,
session-lifetime x3, EmailLabel cross-user invisibility). Full suite: 48/48 green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 03:16:45 +02:00