Learn about our security practices, supported versions, and how to report vulnerabilities.
| Version | Supported |
|---|---|
| 1.20.x | |
| 1.19.x | |
| 1.18.x | |
| < 1.18 | No |
Please do not open a public GitHub issue for security vulnerabilities.
Email security reports to: security@traqify.com or reach the maintainer via @oyedokunken.
Include:
You will receive an acknowledgement within 48 hours and a full response within 7 days.
Short-lived (15 min), signed with JWT_SECRET, stored in localStorage
Long-lived (7 days), stored alongside access tokens
Handled server-side via redirect flow
Required before account activation; expires after 10 minutes
All passwords hashed with bcrypt (cost factor 12)
Four roles with descending privilege: OWNER > MANAGER > CASHIER > AUDITOR
Configured with explicit FRONTEND_URL allowlist
Multer memoryStorage, type restrictions, size limits
Zod schemas on all backend requests
Every create/update/delete action logged
Sensitive values never committed to repository