Files
CompanySite/SECURITY-CHECKLIST.md
T
Clintchiz d402256547
Deploy to Production / Build & Verify (push) Failing after 5m56s
Ping Search Engines / Notify Search Engines (push) Successful in 2s
Deploy to Production / Pre-Deploy Tests (push) Has been skipped
Deploy to Production / Deploy to Railway (push) Has been skipped
Deploy to Production / Deploy to Render (push) Has been skipped
Deploy to Production / Deploy to VPS (PM2) (push) Has been skipped
Deploy to Production / Deploy to Fly.io (push) Has been skipped
Deploy to Production / Post-Deploy Verification (push) Has been skipped
Deploy to Production / Notify on Failure (push) Successful in 2s
E2E Test Suite / Critical User Journeys (push) Has been skipped
E2E Test Suite / API Integration Tests (push) Has been skipped
E2E Test Suite / Smoke Tests (P0) (push) Failing after 11m26s
E2E Test Suite / Form Interaction Tests (push) Failing after 11m42s
E2E Test Suite / Destructive & Chaos Tests (push) Failing after 12m2s
E2E Test Suite / Cross-Browser Regression (chromium) (push) Failing after 16m14s
E2E Test Suite / Cross-Browser Regression (webkit) (push) Failing after 17m45s
E2E Test Suite / Cross-Browser Regression (firefox) (push) Failing after 25m23s
E2E Test Suite / Security Header Tests (push) Failing after 7m55s
E2E Test Suite / Test Report Summary (push) Failing after 20s
E2E Test Suite / Mobile Device Tests (push) Failing after 2h49m9s
Uptime Monitor / Health & Response Time (push) Failing after 2s
Uptime Monitor / SSL Certificate (push) Successful in 2s
Uptime Monitor / Send Alerts (push) Failing after 3s
Uptime Monitor / Record Uptime Success (push) Has been skipped
First Init
2026-03-21 16:46:46 +05:30

8.8 KiB

Security Checklist for WorkRoot IT Solutions

Quick reference guide for security best practices and deployment checklist


Pre-Deployment Security Checklist

Domain Configuration

  • All references use workroot.in (not workroot.com)
  • Canonical URLs point to https://workroot.in
  • Sitemap uses correct domain
  • Structured data (JSON-LD) uses correct domain
  • Open Graph tags use correct domain
  • Domain validation in middleware
  • DNS CAA record configured (optional)
  • HSTS preload submitted (optional)

Security Headers

  • Content-Security-Policy (CSP) configured
  • X-Frame-Options: DENY
  • X-Content-Type-Options: nosniff
  • Referrer-Policy: strict-origin-when-cross-origin
  • Permissions-Policy configured
  • Strict-Transport-Security (HSTS) for production
  • X-Permitted-Cross-Domain-Policies: none
  • X-DNS-Prefetch-Control: on

HTTPS & Certificates

  • Valid SSL/TLS certificate installed
  • Certificate auto-renewal configured
  • HSTS enabled (max-age=31536000)
  • HTTP to HTTPS redirect configured
  • Certificate covers www subdomain (if used)

API Security

  • CORS headers configured for API endpoints
  • API endpoints use HTTPS only
  • Rate limiting implemented (if accepting POST requests)
  • API authentication configured (if needed)
  • Input validation on all endpoints (when backend added)
  • Error messages don't leak sensitive info

Dependencies

  • npm audit run and vulnerabilities fixed
  • Dependencies up to date (npm outdated)
  • package-lock.json committed
  • Automated dependency scanning enabled (Dependabot/Snyk)
  • Regular security updates scheduled

Environment Variables

  • .env file in .gitignore
  • No secrets in source code
  • .env.example provided (no sensitive values)
  • Production environment variables set on hosting platform
  • Secrets manager used for sensitive data (if needed)

External Resources

  • CSP whitelists only trusted domains
  • External resources use crossorigin attribute
  • DNS prefetch/preconnect for external domains
  • Subresource Integrity (SRI) for external scripts (if any)
  • Self-hosting considered for critical resources

Content Security

  • XSS prevention via Astro template escaping
  • CSRF protection (when forms submit to backend)
  • Input sanitization (when backend added)
  • SQL injection prevention (N/A - no database)
  • File upload validation (if implemented)

Monitoring & Logging

  • Security logging middleware enabled
  • Error tracking configured (Sentry, etc.)
  • Access logs monitored
  • Anomaly detection configured
  • Incident response plan documented

Deployment Checklist

Before Going Live

  1. Run npm run build successfully
  2. Run npm audit and fix vulnerabilities
  3. Test security headers (see Testing section below)
  4. Verify HTTPS certificate installed
  5. Check all environment variables set
  6. Review CORS configuration
  7. Test contact form (when backend added)
  8. Verify domain redirects (workroot.com → workroot.in if needed)
  9. Run Playwright security tests: npm run test
  10. Check CSP violations in browser console

After Deployment

  1. Test site at https://workroot.in
  2. Verify security headers: curl -I https://workroot.in
  3. Test with SecurityHeaders.com
  4. Test with SSL Labs: https://www.ssllabs.com/ssltest/
  5. Verify sitemap accessible: https://workroot.in/sitemap.xml
  6. Test structured data with Google Rich Results Test
  7. Monitor error logs for issues
  8. Verify all API endpoints working
  9. Test on multiple browsers/devices
  10. Document any deployment-specific configurations

Testing Security Headers

Manual Testing

# Test security headers
curl -I https://workroot.in

# Test API endpoint
curl https://workroot.in/api/health.json

# Test sitemap
curl https://workroot.in/sitemap.xml

Expected Headers

Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; ...
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

Automated Testing

# Run Playwright security tests
npm run test tests/security-headers.test.ts

# Run all tests
npm run test

Online Security Scanners

  1. SecurityHeaders.com

  2. SSL Labs

  3. CSP Evaluator

  4. Mozilla Observatory


Regular Maintenance Tasks

Weekly

  • Monitor error logs
  • Check for failed security events
  • Review access patterns

Monthly

  • Run npm audit
  • Update dependencies: npm update
  • Review security logs
  • Test security headers still present
  • Check certificate expiry date

Quarterly

  • Full security audit
  • Update SECURITY-AUDIT.md
  • Review and update security policies
  • Penetration testing (if applicable)
  • Review incident response plan
  • Update dependency versions

Annually

  • Comprehensive security review
  • Update security documentation
  • Review access controls
  • Update SSL/TLS certificate (if not auto-renewing)
  • Review OWASP Top 10 compliance

Common Security Issues & Fixes

Issue: CSP Violations in Console

Solution:

  1. Open browser DevTools → Console
  2. Identify blocked resource
  3. If legitimate, add to CSP in src/middleware.ts:
    const csp = [
      // Add new domain to appropriate directive
      "img-src 'self' data: https: https://new-domain.com",
    ].join('; ');
    
  4. Rebuild and redeploy

Issue: Mixed Content Warnings

Solution:

  1. Ensure all resources use HTTPS
  2. Update any HTTP URLs to HTTPS
  3. CSP upgrade-insecure-requests will auto-upgrade
  4. Check external resources (images, fonts, scripts)

Issue: CORS Errors on API

Solution:

  1. Verify Access-Control-Allow-Origin header in API route
  2. Check request origin matches allowed origin
  3. For development, add localhost to allowed origins:
    const origin = isDevelopment ? '*' : 'https://workroot.in';
    headers.set('Access-Control-Allow-Origin', origin);
    

Issue: npm audit Vulnerabilities

Solution:

# Try automatic fix
npm audit fix

# If that doesn't work, fix manually
npm audit fix --force

# Or update specific package
npm update package-name

# Last resort: update to breaking changes
npm install package-name@latest

Issue: Certificate Expiry

Solution:

  1. Renew certificate before expiry (auto-renewal preferred)
  2. Verify certificate includes all domains (including www)
  3. Test after renewal: curl -I https://workroot.in
  4. Check SSL Labs score

Incident Response

If Security Issue Detected

  1. Assess Severity

    • Critical: Data breach, site defacement
    • High: Authentication bypass, XSS
    • Medium: Information disclosure
    • Low: Security header missing
  2. Immediate Actions

    • Document the issue
    • Notify team lead
    • If critical: Take site offline
    • Block malicious IPs (if applicable)
    • Preserve logs for investigation
  3. Investigation

    • Review access logs
    • Check git history
    • Identify attack vector
    • Assess damage/exposure
  4. Remediation

    • Fix vulnerability
    • Update dependencies
    • Deploy patch
    • Reset credentials (if compromised)
    • Clear caches
  5. Post-Incident

    • Document findings
    • Update security measures
    • Notify affected users (if applicable)
    • Review and improve processes
    • Update this checklist

Security Contacts

Internal Security Lead: [Your Name] Email: security@workroot.in Incident Reporting: Create issue at [GitHub repo] Emergency Contact: [Phone number]


Resources

Documentation

Tools

Security Standards

  • OWASP Top 10 (2025)
  • CWE Top 25
  • MITRE ATT&CK Framework
  • NIST Cybersecurity Framework

Last Updated: 2026-03-21 Next Review: 2026-06-21 Version: 1.0