- Added .cursor/sessions/* to .gitignore to prevent session files from being tracked. - Enhanced coding standards in SKILL.md by adding semicolons to TypeScript examples for consistency. - Improved formatting in continuous learning, detail layout, and other SKILL.md files for better readability. These changes aim to streamline development processes and maintain code quality across the project.
2.4 KiB
2.4 KiB
name, description
| name | description |
|---|---|
| security-review | Use this skill when adding authentication, handling user input, working with secrets, or touching Electron IPC. Frontend/Electron security checklist for this SPA monorepo. |
Security Review Skill
Client-side security for this React/Electron frontend. There is no NestJS API or SQL layer in this repo.
When to Activate
- Auth or session handling
- Forms and user input
- Secrets / env vars
- Electron preload / IPC
- Rendering HTML from the server or users
Checklist
1. Secrets
// NEVER
const apiKey = 'sk-proj-xxxxx';
// ALWAYS
import { ENV } from '../environment';
if (!ENV.API_BASE_URL) throw new Error('VITE_API_BASE_URL is not configured');
- No hardcoded secrets
- Env files only under
apps/*/.env*(apps/web/.env.example) - Components use
ENV, not scatteredimport.meta.env - Treat all
VITE_*as public
2. Input validation
Zod + @repo/ui/validators (compose, required, rangeLength) on every form. File uploads: size, MIME, extension allow-lists.
3. XSS
- React text nodes by default
- No unsanitized
dangerouslySetInnerHTML - Sanitize if HTML is required (DOMPurify)
4. Auth
- HTTP only through
apiClient(src/core/lib/api-client) - Session teardown via
terminateAuthSession - Do not log tokens
- Redirect query params encoded
Do not invent httpOnly-cookie APIs this SPA does not own. Token storage follows the existing auth.helper + storage adapters.
5. Electron (apps/desktop)
contextIsolation: truenodeIntegration: falsesandbox: true- No new Node APIs on
windowoutside preload
6. Sensitive data
- No tokens or passwords in logs
- Generic user-facing errors; details in telemetry only
7. Dependencies
pnpm audit
- Lockfile committed
- No known high/critical issues without a documented exception
Out of scope (backend)
Do not spend review time on SQL injection, Drizzle, CSRF-on-API-routes, or API rate limits. Flag them only if this client is clearly bypassing the API contract.
Resources
Remember: One XSS or leaked VITE_ secret in the client is enough. Prefer the existing apiClient and ENV wrappers.