M7: Hardening #55
Labels
No labels
area:backend
area:frontend
area:infra
area:ocr
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
phase:M1
phase:M2
phase:M3
phase:M4
phase:M5
phase:M6
phase:M7
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
TJC/bill-splitter#55
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Goal
Production readiness: rate limits, upload hardening, security headers, caps, no-PII audit, Puppeteer e2e, prod compose, and a real deploy.
Scope
Rate limit policies, upload sniffing + decode-bomb guard, security headers, caps enforcement, no-PII log audit, Puppeteer e2e specs, prod compose + .env.example, deploy.
References
Acceptance criteria (docs/14)
Retry-After)redis-cli --scanempty, MinIO bucket emptyNotes
Rate limits + upload hardening + headers land before e2e/deploy; prod compose + Dockerfile precede the e2e job and the deploy; ephemerality verification is the final gate.
Sub-tasks are tracked as sub-issues below.