Skip to content

Security: senior-13j/cryptoearner

Security

SECURITY.md

Security

Production Boundaries

Crypto Earner is a non-custodial decision-support and paper-trading workstation. The client must not store private keys, seed phrases, exchange API keys, withdrawal credentials, or Stripe secret keys.

Live exchange execution is intentionally not implemented in the browser or Electron renderer. Add a reviewed server-side exchange adapter, encrypted key storage, explicit confirmation, and a kill switch before enabling real leveraged orders.

Required Production Controls

  • Configure Vercel secrets: VERCEL_TOKEN, VERCEL_ORG_ID, VERCEL_PROJECT_ID.
  • Configure Stripe server-only variables only in Vercel, never as VITE_* variables.
  • Set APP_URL=https://cryptoearner.vercel.app.
  • Set PORTAL_ACCESS_SECRET before enabling /api/create-portal-session.
  • Keep VITE_ALLOWED_REDIRECT_HOSTS limited to trusted app domains.
  • Add every custom Solana RPC host to connect-src in index.html and vercel.json before using it in production.
  • Keep the service worker cache restricted to static app shell assets. It must not cache /api/*, POST requests, checkout sessions, portal sessions, or webhook traffic.
  • Protect main and require CODEOWNERS review for .github/workflows/*, api/*, electron/*, PWA files, vercel.json, and dependency lockfiles.

Local Verification

docker compose run --rm web npm run check
docker compose run --rm e2e
docker compose run --rm web npm audit
docker compose run --rm web npm audit --omit=dev
git diff --check

Browser QA should confirm:

  • No console errors.
  • No horizontal overflow on mobile and tablet.
  • PWA manifest and service worker are available in production preview.
  • Demo SSO works.
  • Subscription test flow requires risk acknowledgement.
  • Custody flow blocks without connected Phantom.
  • Order-flow detailed gates render before paper execution.
  • SEO/PWA metadata files are served without leaking secrets and llms.txt keeps the product positioned as decision support, not guaranteed-profit automation.

Reporting

Do not open public issues for suspected secrets, key leakage, auth bypass, payment bypass, or wallet-flow vulnerabilities. Report privately to the repository owner and rotate any exposed credentials immediately.

There aren't any published security advisories