Web Application Security
Core application security controls covering authentication, authorization, session handling, input validation, and API routes.
Audit Progress: 0 of 10 verified
Check off items as you verify them in your codebase. Progress is saved locally.
Passwords are securely hashed server-side
Verify that passwords are never stored in plaintext or reversibly encrypted, and use a strong salt-per-user hashing algorithm like Argon2id or bcrypt.
Login & sensitive routes have rate limiting
Protect login, password reset, and sensitive endpoints against brute-force attacks and credential stuffing.
MFA / 2FA verification cannot be bypassed
Ensure multi-factor authentication controls are strictly enforced server-side and cannot be skipped by manipulating client requests.
Server-side authorization on all direct object access (IDOR)
Validate that every endpoint accepting a record ID checks user ownership or organisation membership before returning or modifying data.
Session cookies use HttpOnly, Secure, and SameSite flags
Protect session identifiers from cross-site scripting (XSS) and cross-site request forgery (CSRF) using strict cookie security attributes.
Database queries are parameterized against SQL/NoSQL injection
Ensure user input is never concatenated directly into SQL queries or dynamic database command strings.
User-generated HTML/Markdown is sanitized against XSS
Prevent Reflected and Stored Cross-Site Scripting by escaping or sanitizing any user input rendered in the browser.
No production API keys or secrets in frontend bundles
Verify that service role keys, database connection strings, and private API keys are not exposed in public environment variables or client builds.
File uploads validate size, extension, and MIME type
Restrict uploaded files to safe types, isolate storage outside web roots, and enforce file size constraints.
Server Actions and Route Handlers verify authentication & authorization
Ensure Next.js Server Actions and API Route Handlers independently verify the user's session before performing state changes.