SECURITY REQUIREMENTS:

1. INPUT VALIDATION & SANITIZATION
– Sanitize and validate ALL user inputs on both frontend and backend.
– Prevent:
– SQL Injection
– NoSQL Injection
– XSS (Stored, Reflected, DOM)
– Command Injection
– LDAP Injection
– Template Injection
– Path Traversal
– File Upload Exploits
– Never trust client-side validation alone.
– Escape all outputs before rendering HTML.
– Strip dangerous HTML, scripts, inline events, and malicious payloads.

2. DATABASE SECURITY
– Use ONLY parameterized queries / prepared statements.
– NEVER concatenate SQL queries directly with user input.
– Use ORM safe methods where possible.
– Prevent mass assignment vulnerabilities.
– Hide database errors from users.
– Use least-privilege database accounts.

3. AUTHENTICATION & AUTHORIZATION
– Use secure authentication flows.
– Store passwords only with bcrypt or Argon2 hashing.
– Enforce:
– strong passwords
– rate limiting
– login throttling
– account lockout after repeated failures
– Use secure JWT/session handling.
– Sessions must use:
– HttpOnly cookies
– Secure flag
– SameSite protection
– Implement CSRF protection everywhere.
– Add optional 2FA support.

4. API SECURITY
– Validate every API request.
– Add API rate limiting.
– Prevent API abuse and brute force attacks.
– Use authentication middleware.
– Reject malformed JSON and oversized payloads.
– Never expose secrets or API keys in frontend code.

5. FILE UPLOAD SECURITY
– Allow only whitelisted file types.
– Validate MIME type and extension.
– Rename uploaded files securely.
– Store uploads outside executable directories.
– Scan uploads for malware if possible.
– Prevent double-extension attacks.

6. FRONTEND SECURITY
– Enable strict Content Security Policy (CSP).
– Disable inline JavaScript where possible.
– Prevent clickjacking using:
– X-Frame-Options
– frame-ancestors CSP
– Enable:
– X-Content-Type-Options
– Referrer-Policy
– Permissions-Policy
– Sanitize all dynamic HTML rendering.
– Avoid dangerous innerHTML usage.

7. BACKEND SECURITY
– Hide stack traces and internal server errors.
– Use centralized error handling.
– Implement audit logging.
– Add intrusion detection patterns.
– Prevent remote code execution vulnerabilities.
– Validate all headers, cookies, and request bodies.
– Block suspicious payloads and attack signatures.

8. SERVER & INFRASTRUCTURE SECURITY
– Force HTTPS everywhere.
– Enable HSTS.
– Disable directory listing.
– Secure CORS configuration.
– Disable unnecessary ports/services.
– Store secrets in environment variables only.
– Never hardcode passwords, API keys, or tokens.
– Add automatic security headers.

9. ANTI-BOT & DDOS PROTECTION
– Add CAPTCHA on sensitive forms.
– Add request throttling.
– Detect abnormal traffic behavior.
– Add bot protection middleware.

10. LOGGING & MONITORING
– Log:
– failed logins
– suspicious requests
– permission violations
– API abuse
– Never log passwords or sensitive personal data.
– Create security alerts for suspicious activities.

11. SECURE CODING RULES
– Follow OWASP Top 10 best practices.
– Follow secure-by-default architecture.
– Avoid vulnerable dependencies.
– Automatically check packages for vulnerabilities.
– Use TypeScript strict mode if applicable.
– Generate modular, maintainable, and secure code.

12. HEADERS TO ENABLE
– Content-Security-Policy
– Strict-Transport-Security
– X-Frame-Options
– X-Content-Type-Options
– Referrer-Policy
– Permissions-Policy

13. ADD SECURITY MIDDLEWARE
If using:
– Express.js → helmet, express-rate-limit, csurf
– Next.js → secure headers middleware
– Laravel → CSRF + validation middleware
– WordPress → nonce validation + sanitization + escaping
– React → sanitize dynamic content
– Node.js → validation middleware on every route

14. OUTPUT REQUIREMENTS
– Generate secure production-ready code.
– Explain every implemented security mechanism.
– Add comments describing anti-injection protections.
– Include examples of sanitized queries and secure API endpoints.
– Include secure authentication examples.
– Include secure upload handling examples.
– Include CSP configuration examples.
– Include rate-limiting examples.
– Include secure environment variable usage.
– Include anti-XSS rendering examples.

15. WORDPRESS/WOOCOMMERCE SECURITY (IF RELEVANT)
– Use:
– sanitize_text_field()
– esc_html()
– esc_attr()
– wp_nonce_field()
– check_admin_referer()
– wp_verify_nonce()
– prepare()
– Prevent direct access to PHP files.
– Protect AJAX endpoints.
– Validate REST API permissions.
– Escape ALL output properly.
– Prevent privilege escalation.
– Disable XML-RPC if unused.

16. FINAL SECURITY CHECK
Before final output:
– scan code for vulnerabilities
– check OWASP compliance
– validate secure headers
– verify injection protection
– verify authentication security
– verify authorization logic
– verify file upload protections
– verify API security
– verify session security

Generate the most secure architecture possible.
Security must be enabled by default, not optional.

האתר נעזר ב"עוגיות" (cookies) לשיפור איכות חווית הגלישה שלך. המשך גלישה מהווה הסכמתך לשימוש בהם.

בניית אתרים וקידום עסקים באינטרנט Site2goal

הי!

רגע לפני שעוזבים
השאירו פרטים ונשמח לעזור