# Security Checklist for WorkRoot IT Solutions > Quick reference guide for security best practices and deployment checklist --- ## Pre-Deployment Security Checklist ### ✅ Domain Configuration - [x] All references use `workroot.in` (not `workroot.com`) - [x] Canonical URLs point to `https://workroot.in` - [x] Sitemap uses correct domain - [x] Structured data (JSON-LD) uses correct domain - [x] Open Graph tags use correct domain - [x] Domain validation in middleware - [ ] DNS CAA record configured (optional) - [ ] HSTS preload submitted (optional) ### ✅ Security Headers - [x] Content-Security-Policy (CSP) configured - [x] X-Frame-Options: DENY - [x] X-Content-Type-Options: nosniff - [x] Referrer-Policy: strict-origin-when-cross-origin - [x] Permissions-Policy configured - [x] Strict-Transport-Security (HSTS) for production - [x] X-Permitted-Cross-Domain-Policies: none - [x] X-DNS-Prefetch-Control: on ### ✅ HTTPS & Certificates - [ ] Valid SSL/TLS certificate installed - [ ] Certificate auto-renewal configured - [ ] HSTS enabled (max-age=31536000) - [ ] HTTP to HTTPS redirect configured - [ ] Certificate covers www subdomain (if used) ### ✅ API Security - [x] CORS headers configured for API endpoints - [x] API endpoints use HTTPS only - [x] Rate limiting implemented (if accepting POST requests) - [ ] API authentication configured (if needed) - [ ] Input validation on all endpoints (when backend added) - [ ] Error messages don't leak sensitive info ### ✅ Dependencies - [ ] `npm audit` run and vulnerabilities fixed - [ ] Dependencies up to date (`npm outdated`) - [ ] `package-lock.json` committed - [ ] Automated dependency scanning enabled (Dependabot/Snyk) - [ ] Regular security updates scheduled ### ✅ Environment Variables - [x] `.env` file in `.gitignore` - [x] No secrets in source code - [x] `.env.example` provided (no sensitive values) - [ ] Production environment variables set on hosting platform - [ ] Secrets manager used for sensitive data (if needed) ### ✅ External Resources - [x] CSP whitelists only trusted domains - [x] External resources use `crossorigin` attribute - [x] DNS prefetch/preconnect for external domains - [ ] Subresource Integrity (SRI) for external scripts (if any) - [ ] Self-hosting considered for critical resources ### ✅ Content Security - [x] XSS prevention via Astro template escaping - [ ] CSRF protection (when forms submit to backend) - [ ] Input sanitization (when backend added) - [ ] SQL injection prevention (N/A - no database) - [ ] File upload validation (if implemented) ### ✅ Monitoring & Logging - [ ] Security logging middleware enabled - [ ] Error tracking configured (Sentry, etc.) - [ ] Access logs monitored - [ ] Anomaly detection configured - [ ] Incident response plan documented --- ## Deployment Checklist ### Before Going Live 1. [ ] Run `npm run build` successfully 2. [ ] Run `npm audit` and fix vulnerabilities 3. [ ] Test security headers (see Testing section below) 4. [ ] Verify HTTPS certificate installed 5. [ ] Check all environment variables set 6. [ ] Review CORS configuration 7. [ ] Test contact form (when backend added) 8. [ ] Verify domain redirects (workroot.com → workroot.in if needed) 9. [ ] Run Playwright security tests: `npm run test` 10. [ ] Check CSP violations in browser console ### After Deployment 1. [ ] Test site at `https://workroot.in` 2. [ ] Verify security headers: `curl -I https://workroot.in` 3. [ ] Test with SecurityHeaders.com 4. [ ] Test with SSL Labs: https://www.ssllabs.com/ssltest/ 5. [ ] Verify sitemap accessible: `https://workroot.in/sitemap.xml` 6. [ ] Test structured data with Google Rich Results Test 7. [ ] Monitor error logs for issues 8. [ ] Verify all API endpoints working 9. [ ] Test on multiple browsers/devices 10. [ ] Document any deployment-specific configurations --- ## Testing Security Headers ### Manual Testing ```bash # Test security headers curl -I https://workroot.in # Test API endpoint curl https://workroot.in/api/health.json # Test sitemap curl https://workroot.in/sitemap.xml ``` ### Expected Headers ``` Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; ... X-Frame-Options: DENY X-Content-Type-Options: nosniff Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=31536000; includeSubDomains; preload ``` ### Automated Testing ```bash # Run Playwright security tests npm run test tests/security-headers.test.ts # Run all tests npm run test ``` ### Online Security Scanners 1. **SecurityHeaders.com** - URL: https://securityheaders.com/?q=https://workroot.in - Expected: A+ grade 2. **SSL Labs** - URL: https://www.ssllabs.com/ssltest/analyze.html?d=workroot.in - Expected: A or A+ grade 3. **CSP Evaluator** - URL: https://csp-evaluator.withgoogle.com/ - Paste CSP header from site 4. **Mozilla Observatory** - URL: https://observatory.mozilla.org/ - Expected: A or A+ grade --- ## Regular Maintenance Tasks ### Weekly - [ ] Monitor error logs - [ ] Check for failed security events - [ ] Review access patterns ### Monthly - [ ] Run `npm audit` - [ ] Update dependencies: `npm update` - [ ] Review security logs - [ ] Test security headers still present - [ ] Check certificate expiry date ### Quarterly - [ ] Full security audit - [ ] Update SECURITY-AUDIT.md - [ ] Review and update security policies - [ ] Penetration testing (if applicable) - [ ] Review incident response plan - [ ] Update dependency versions ### Annually - [ ] Comprehensive security review - [ ] Update security documentation - [ ] Review access controls - [ ] Update SSL/TLS certificate (if not auto-renewing) - [ ] Review OWASP Top 10 compliance --- ## Common Security Issues & Fixes ### Issue: CSP Violations in Console **Solution**: 1. Open browser DevTools → Console 2. Identify blocked resource 3. If legitimate, add to CSP in `src/middleware.ts`: ```typescript const csp = [ // Add new domain to appropriate directive "img-src 'self' data: https: https://new-domain.com", ].join('; '); ``` 4. Rebuild and redeploy ### Issue: Mixed Content Warnings **Solution**: 1. Ensure all resources use HTTPS 2. Update any HTTP URLs to HTTPS 3. CSP `upgrade-insecure-requests` will auto-upgrade 4. Check external resources (images, fonts, scripts) ### Issue: CORS Errors on API **Solution**: 1. Verify `Access-Control-Allow-Origin` header in API route 2. Check request origin matches allowed origin 3. For development, add localhost to allowed origins: ```typescript const origin = isDevelopment ? '*' : 'https://workroot.in'; headers.set('Access-Control-Allow-Origin', origin); ``` ### Issue: npm audit Vulnerabilities **Solution**: ```bash # Try automatic fix npm audit fix # If that doesn't work, fix manually npm audit fix --force # Or update specific package npm update package-name # Last resort: update to breaking changes npm install package-name@latest ``` ### Issue: Certificate Expiry **Solution**: 1. Renew certificate before expiry (auto-renewal preferred) 2. Verify certificate includes all domains (including www) 3. Test after renewal: `curl -I https://workroot.in` 4. Check SSL Labs score --- ## Incident Response ### If Security Issue Detected 1. **Assess Severity** - Critical: Data breach, site defacement - High: Authentication bypass, XSS - Medium: Information disclosure - Low: Security header missing 2. **Immediate Actions** - Document the issue - Notify team lead - If critical: Take site offline - Block malicious IPs (if applicable) - Preserve logs for investigation 3. **Investigation** - Review access logs - Check git history - Identify attack vector - Assess damage/exposure 4. **Remediation** - Fix vulnerability - Update dependencies - Deploy patch - Reset credentials (if compromised) - Clear caches 5. **Post-Incident** - Document findings - Update security measures - Notify affected users (if applicable) - Review and improve processes - Update this checklist --- ## Security Contacts **Internal Security Lead**: [Your Name] **Email**: security@workroot.in **Incident Reporting**: Create issue at [GitHub repo] **Emergency Contact**: [Phone number] --- ## Resources ### Documentation - [SECURITY-AUDIT.md](./SECURITY-AUDIT.md) - Full security audit report - [Astro Security Guide](https://docs.astro.build/en/guides/security/) - [OWASP Top 10](https://owasp.org/www-project-top-ten/) ### Tools - [npm audit](https://docs.npmjs.com/cli/v8/commands/npm-audit) - [Snyk](https://snyk.io/) - Dependency scanning - [Dependabot](https://github.com/dependabot) - Auto dependency updates - [SecurityHeaders.com](https://securityheaders.com/) - [SSL Labs](https://www.ssllabs.com/ssltest/) ### Security Standards - OWASP Top 10 (2025) - CWE Top 25 - MITRE ATT&CK Framework - NIST Cybersecurity Framework --- **Last Updated**: 2026-03-21 **Next Review**: 2026-06-21 **Version**: 1.0