Location
repo-wide, tracked via SECURITY_AUDIT.md
Problem
The README flags secret-key encryption specifically, but a broader audit is needed covering JWT_SECRET, database credentials, and any other sensitive configuration to confirm nothing else is under-protected in a similar way.
Acceptance Criteria
Location
repo-wide, tracked via SECURITY_AUDIT.md
Problem
The README flags secret-key encryption specifically, but a broader audit is needed covering JWT_SECRET, database credentials, and any other sensitive configuration to confirm nothing else is under-protected in a similar way.
Acceptance Criteria