Skip to content

fix(security): harden Portall for public deployment - #116

Merged
iDrinkx merged 2 commits into
mainfrom
security-hardening
Oct 4, 2026
Merged

iDrinkx merged 2 commits into
mainfrom
security-hardening

Conversation

@iDrinkx

@iDrinkx iDrinkx commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Security hardening

Large security hardening pass for Portall before public deployment.

Main changes

  • Fixed Plex admin bootstrap privilege issue
  • Session fixation protection and CSRF hardening
  • Encrypted application secrets and SQLite sessions at rest
  • Replaced http-proxy-middleware with hardened httpxy Jellyfin proxy
  • Hardened HTTP and WebSocket authentication
  • SSRF protections extended
  • Removed vulnerable/unused dependencies
  • Replaced semantic-release with Release Please
  • Removed committed test databases
  • Hardened Docker runtime and configuration
  • Migrated unsafe frontend HTML renderers to DOM APIs
  • Added XSS and frontend sink regression tests
  • Added dedicated Security CI

Validation

  • 21/21 tests passing
  • npm audit: 0 vulnerabilities
  • npm audit --omit=dev: 0 vulnerabilities
  • Docker image builds successfully
  • Runtime container smoke test passes
  • Runtime image content checks pass
  • Security headers validated
  • Sensitive paths are not exposed
  • Runtime process verified non-root

Notes

The previous failed Security CI run was caused by the CI smoke test not forwarding generated secrets to Docker. This was corrected in ad26c11; the subsequent full Security CI run passes.

@iDrinkx
iDrinkx merged commit ff8b401 into main Oct 4, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant