Security audit

A CLI or API, that would carry out a security audit on the Wappler project to detect common security issues, such as:

  1. Missed security restricts for API
  2. Missing Permission and Validations
  3. Credentials hard coded in API steps instead of env variables,
    etc,etc

This would be helpful when Integrating the CI/CD pipelines in DevSecOps or NoOps

Adding a couple of more checks that can be included here:

  1. Debug flag on
  2. Outputs on for Insert or Update Operations (Warnings)
  3. Cookies not set to Strict, samesite
  4. DB connections not using SSL
  5. Passwords not using hashing
  6. Comments in Pages
1 Like

Bump!!!

Bump!

Bump!

Bump!!!

When you realise at 3am that you forgot you enabled debug…

UyHrWY1

5 Likes

Hi @George @patrick,
any update on this feature?

2 Likes

Bump!!!

I voted on this a while ago, if this is possible it would be a great help so securing our work. I’ve just been through some stuff I did a good while ago and a lot of it had missing security on APIs - it was easy enough to sort out but having an overview given by an audit facility would be way clearer.

1 Like

Bump!!! :smiley:

2 Likes

Bump!!!

1 Like