Security Policy

Learn about our security practices, supported versions, and how to report vulnerabilities.

Supported Versions

VersionSupported
1.20.x
1.19.x
1.18.x
< 1.18No

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Email security reports to: security@traqify.com or reach the maintainer via @oyedokunken.

Include:

  • A clear description of the vulnerability
  • Steps to reproduce
  • Potential impact assessment
  • Any suggested fix (optional)

You will receive an acknowledgement within 48 hours and a full response within 7 days.

Authentication

JWT Access Tokens

Short-lived (15 min), signed with JWT_SECRET, stored in localStorage

Refresh Tokens

Long-lived (7 days), stored alongside access tokens

Google OAuth 2.0

Handled server-side via redirect flow

OTP Email Verification

Required before account activation; expires after 10 minutes

Password Hashing

All passwords hashed with bcrypt (cost factor 12)

Authorization (RBAC)

Four roles with descending privilege: OWNER > MANAGER > CASHIER > AUDITOR

  • Route-level enforcement via authenticate and RBAC Express middleware
  • All authenticated routes require a valid JWT; expired tokens are rejected with 401
  • Organization scope is enforced on every query
  • OWNER protection: the OWNER account cannot be restricted, removed, or have their password reset
  • Invite role cap: OWNER role can never be assigned via invitation

Additional Security Measures

CORS

Configured with explicit FRONTEND_URL allowlist

File Uploads

Multer memoryStorage, type restrictions, size limits

Input Validation

Zod schemas on all backend requests

Audit Logging

Every create/update/delete action logged

Environment Variables

Sensitive values never committed to repository