Production › Security

Security

#Reporting a vulnerability

Please report privately (GitHub Security Advisories → "Report a vulnerability", or security@nestlaravel.dev). Do not open public issues for vulnerabilities. We acknowledge within 72 hours and coordinate disclosure.

#Threat model in one page

PUBLIC     apps/api                 the only internet-facing process
INTERNAL   apps/<name>-service      never published; reachable only from the gateway network
SERVICE-TO-SERVICE                  gateway → service: HMAC-signed HTTP · service ↔ service: Kafka (TLS+SASL+ACL)
ADMIN      artisan, Kafka UI, DB    private network / VPN only; tenancy bypass is explicit code (`withoutTenancy`)

An attacker who can reach a service port directly must still fail: every request needs a signature made with that service's private secret, bound to method + path + query + body hash + user + tenant, valid for 60 s, single-use. A service without a configured secret answers 503 (fail closed). Never publish service ports and keep them on a private network as defence in depth.

#Controls (built in)

AreaControl
AuthnSanctum bearer tokens, 24 h expiry (SANCTUM_TOKEN_EXPIRATION), bcrypt (cost 12), Password::defaults()
AuthzRoles/permissions (permission: middleware, gates). Self-registration may only grant auth.self_registration_roles (default customer); privileged roles are admin-assigned
Brute forcethrottle:auth: 10/min per IP, 5/min per account+IP, 30/h per account; throttle:api 60/min per user; mcp 30/min
InputFormRequest validation; DTOs; Eloquent bindings (no raw SQL); gateway path sanitiser (.., control chars, %2e, %2f)
SSRFGateway only calls configured base URLs, never follows redirects, ignores client-supplied hosts
Mass assignmentexplicit $fillable; tenant column is never mass-assignable
CORS / CSRFExplicit origin allow-list (CORS_ALLOWED_ORIGINS); stateless token API, no cookie auth on /api
Headersnosniff, X-Frame-Options: DENY, CSP, Referrer-Policy, COOP/CORP, Permissions-Policy
Secretsnone in source; .env git-ignored, excluded from Docker context and the npm package; create generates unique APP_KEY, DB, Redis and per-service signing secrets
ErrorsAPP_DEBUG=false by default; 5xx bodies are generic; health output omits broker addresses
KafkaTLS/SASL settings, acks=all + idempotence, manual commits, DLQ, schema-version guard (see KAFKA.md)
Containerspinned images, infra ports on 127.0.0.1, Redis requirepass, Postgres role+database per service, server_tokens off
Supply chaincomposer audit / npm audit in CI; npm publish with provenance; template secret-scan blocks release

#Production checklist

#Audit summary for 1.0.0

Full write-up of findings and fixes is in the release notes (CHANGELOG.md). Highlights: self-service privilege escalation to platform_admin (Critical, fixed), unauthenticated gateway → unauthenticated internal services (Critical, fixed with signed service auth), outbox marked messages published before broker confirmation (High, fixed), missing production Kafka consumer/TLS/SASL (High, added), vulnerable transitive packages (High, updated), default credentials in Compose files (Medium, removed).

Known limitations: no rate limit on service-to-service traffic beyond the gateway's; portals still use localStorage; single outbox publisher per service; metrics endpoint not included (use your APM/OTel agent).

Edit this page on GitHub