Skip to main content

Security

Hard rules for this product. Do not weaken them in docs examples.

Payments​

Never store a full card number or CVV. Checkout collects last four and brand. Paystack keeps the PAN.

The Paystack webhook stays public and HMAC-verified (timing-safe compare). Do not put it behind JWT.

Host​

Production Node listens on 127.0.0.1 only. Caddy terminates TLS on 80/443. /api/docs is off in production. UFW plus Lightsail networking should allow 22 (your IP), 80, and 443 — not 4000 or 5432. Do not open RDS to 0.0.0.0/0.

Auth and uploads​

New upload routes require JWT. Company-scoped resources must check membership. Do not add unauthenticated file writes.

Platform staff (SUPER_ADMIN, ADMIN, STAFF) manage the catalog, people, companies, and godfather billing from /admin. They are not OS operators and must not be invited into a company. OS operators (USER) must not reach /admin.

Owner portal and tenant portal require JWT. Access is an invite row (OwnerPortalAccess / TenantPortalAccess), not company membership.

Catalog honesty​

Do not sell a SKU that has no screen. Coming-soon catalog products stay COMING_SOON with a coming-soon page. Never route those SKUs to stub headings.

Secrets​

Do not put PAYSTACK_SECRET_KEY in the frontend. Do not commit .env files. Local setup notes in Shipping list variable names only. Production topology: Production setup. RDS should not be open to 0.0.0.0/0 to "enable Hyperdrive."