Skip to content

Security hardening: restrict public endpoints and improve CI coverage - #375

Open
iSanae1 wants to merge 4 commits into
shuaiplus:mainfrom
iSanae1:dev
Open

iSanae1 wants to merge 4 commits into
shuaiplus:mainfrom
iSanae1:dev

Conversation

@iSanae1

@iSanae1 iSanae1 commented Sep 12, 2026

Copy link
Copy Markdown

Summary

This PR improves the security defaults and CI coverage of the NodeWarden fork.

  • Disable the default workers.dev route and preview URLs in both R2 and KV Wrangler configurations.
  • Update Cloudflare tooling and patched dependency versions.
  • Disable password-hint disclosure by default while retaining an explicit PASSWORD_HINTS_ENABLED=1 compatibility option.
  • Run CodeQL and the extra security workflow for pull requests.
  • Allow both security workflows to be started manually with workflow_dispatch.

Security impact

The Worker is no longer exposed through automatically generated workers.dev or preview hostnames when deployed with the included Wrangler configuration.

Password-hint requests return a non-disclosing response by default. Existing deployments can explicitly restore the previous behavior by setting:

PASSWORD_HINTS_ENABLED=1

Validation

  • CodeQL Advanced passed for GitHub Actions and JavaScript/TypeScript.
  • Extra Security Scan passed.
  • Worker and shared TypeScript checks passed.
  • Web application TypeScript checks passed.
  • Existing automated tests passed: 31 tests, 0 failures, 0 skipped.
  • Vite production build completed successfully.
  • npm audit --audit-level=high reported no known vulnerabilities.

Deployment notes

This PR does not deploy the Worker or change Cloudflare account settings. Deployments using Cloudflare Git integration should verify that main is the intended production branch before merging.

Out of scope

This PR does not change the existing Semgrep enforcement behavior. The dependency audit workflow currently remains unchanged and can be aligned with the repository's package-lock.json in a separate CI-focused change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant