b176a44627
Active docs/ was stub scaffolding while the real docs sat in docs/_archive/. Restore and correct them, and record the Phase 0 work. - docs/architecture/current.md: verified system map (from archived SYSTEM_OVERVIEW, 9 corrections against code). - docs/research/competitors.md: sourced competitor analysis (from archived PRODUCT_RESEARCH, feature matrix corrected). - docs/decisions/ADR-002-job-application-model.md: the Job/JobApplication split. - docs/application-discovery-report.md, docs/implementation-roadmap.md, docs/phase-0-foundation-report.md, docs/career-workspace-branch-assessment.md. - Remove 10 zero-byte placeholder files that advertised content that never existed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
926 B
926 B
Security Overview
Purpose
Define security requirements for Jobjakt.
The application stores sensitive career information including:
- CVs.
- Employment history.
- Personal details.
- Job applications.
- Documents.
- Communication.
Security must be considered a core product requirement.
Security Goals
Jobjakt should provide:
- Secure authentication.
- Strong user separation.
- Safe document handling.
- Protected APIs.
- Secure AI integrations.
Security Principles
Least Privilege
Users should only access their own data.
Admins have additional permissions.
Secure By Default
Features should default to safe behaviour.
Validate Everything
All external input should be considered untrusted.
Sources:
- Forms.
- APIs.
- Uploaded files.
- AI responses.
- Imported job descriptions.
Do Not Over-Engineer
Security should protect users without harming usability.