Commit Graph

3 Commits

Author SHA1 Message Date
af52c33617 Add security fixes and deployment configuration
Security fixes:
- Remove hardcoded MongoDB credentials from server.js (fail fast in production)
- Add OAuth state parameter validation for CSRF protection
- Add input validation for unitCode parameter to prevent NoSQL injection
- Add isValidUnitCode helper function

Deployment:
- Update docker-compose.yml to use env_file and environment variables
- Create .env.example with all required configuration variables
2026-01-21 18:04:37 -07:00
ca281ba5b6 Add user activity logging system
- Create services/activityLogger.js with configurable log levels (all, navigation, none)
- Create routes/activity.js with endpoints for logging and admin statistics
- Integrate login/logout activity logging into auth routes
- Add TTL index for automatic 90-day cleanup of activity records
- Mount activity routes at /activity
2026-01-21 17:53:56 -07:00
67f2d9a12e Add Google OAuth authentication infrastructure
- Add passport, passport-google-oauth20, jsonwebtoken, cookie-parser, uuid deps
- Create config/auth.js with JWT, cookie, and OAuth configuration
- Create models/user.js with MongoDB user model and indexes
- Create middleware/passport.js with Google OAuth strategy
- Create middleware/auth.js with requireAuth middleware and sliding window refresh
- Create routes/auth.js with OAuth flow endpoints
- Update server.js to integrate auth, protect all data endpoints (except /health)
- Configure CORS for cookie-based authentication
2026-01-21 16:45:34 -07:00