Security
Hard rules for this product. Do not weaken them in docs examples.
Payments
Never store a full card number or CVV. Checkout collects last four and brand. Paystack keeps the PAN.
The Paystack webhook stays public and HMAC-verified (timing-safe compare). Do not put it behind JWT.
Host
Production Node listens on 127.0.0.1 only. Caddy terminates TLS on
80/443. /api/docs is off in production. UFW plus Lightsail networking
should allow 22 (your IP), 80, and 443 — not 4000 or 5432. Do not open
RDS to 0.0.0.0/0.
Auth and uploads
New upload routes require JWT. Company-scoped resources must check membership. Do not add unauthenticated file writes.
Platform staff (SUPER_ADMIN, ADMIN, STAFF) manage the catalog,
people, companies, and godfather billing from /admin. They are not OS
operators and must not be invited into a company. OS operators (USER)
must not reach /admin.
Owner portal and tenant portal require JWT. Access is an invite row
(OwnerPortalAccess / TenantPortalAccess), not company membership.
Catalog honesty
Do not sell a SKU that has no screen. Coming-soon catalog products stay
COMING_SOON with a coming-soon page. Never route those SKUs to stub
headings.
Secrets
Do not put PAYSTACK_SECRET_KEY in the frontend. Do not commit .env
files. Local setup notes in Shipping list
variable names only. Production topology:
Production setup. RDS should not be open
to 0.0.0.0/0 to "enable Hyperdrive."