Files
property-management-network/.dockerignore
T
Leon SerfatyandClaude Opus 4.8 969d5d4c8a Security hardening from 2026-07-01 audit
- Exclude supabase/ from Docker build context (leaked service_role key file)
- /api/files: exact per-user namespace match + reject path traversal;
  storage resolveKey rejects ".."/"." segments (fixes cross-user file read)
- Add ownsProperty/Unit/Tenant checks to tenants, maintenance (landlord path),
  and documents (JSON branch, now field-whitelisted) create handlers
- Escape user data in follow-up + payment-link emails (reuse escapeHtml)
- Neutralize CSV formula injection in toCsv + export routes
- Tighter sign-in rate limit (10/min); env-gated email verification + sender
- Per-request nonce CSP; drop script-src 'unsafe-inline' (styles unchanged)
- Add input length bounds; validate follow-ups POST body

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01 13:56:34 -04:00

37 lines
545 B
Plaintext

# Dependencies & build output (reinstalled / rebuilt inside the image)
node_modules
.next
out
build
coverage
# Secrets — never bake env files into the image
.env
.env.*
supabase
# Local file storage (uploads live on a mounted volume, not in the image)
storage
# Version control & tooling
.git
.gitignore
.gitattributes
.vercel
*.tsbuildinfo
# Editor / OS noise
.DS_Store
.vscode
.idea
# Docs not needed at runtime
DOCS
README.md
COOLIFY.md
# Don't copy the Docker context files into the image
Dockerfile
.dockerignore
docker-compose.yml