Skip to content

How it works

This page describes the security model: what LynxPrompt does to protect accounts, data and the API. The stack and the code layout are in Development.

Security Measures Implemented

1. Authentication & Authorization

NextAuth.js Configuration

  • Session Strategy: Database sessions with secure cookie settings
  • Secure Cookies: __Secure- prefix in production, HttpOnly, SameSite=Lax
  • Session Lifetime: 30-day max age with 24-hour refresh interval
  • Role-Based Access: USER, ADMIN, SUPERADMIN roles

OAuth Providers

  • GitHub OAuth with proper callback validation
  • Google OAuth (optional)
  • Magic Link email authentication

Passkeys (WebAuthn)

  • FIDO2/WebAuthn support for passwordless authentication
  • Challenge-based authentication to prevent replay attacks
  • Credential storage with counter tracking

2. API Security

Rate Limiting

  • General requests: 100/minute per IP
  • Auth endpoints: 10/minute per IP
  • 429 responses with Retry-After headers

Input Validation

  • Prisma ORM prevents SQL injection
  • Type validation via TypeScript
  • API routes validate required parameters

3. HTTP Security Headers

All responses include:

  • X-Frame-Options: DENY - Prevents clickjacking
  • X-Content-Type-Options: nosniff - Prevents MIME sniffing
  • X-XSS-Protection: 1; mode=block - XSS filter
  • Referrer-Policy: strict-origin-when-cross-origin
  • Permissions-Policy - Disables camera, microphone, geolocation, payment
  • Content-Security-Policy - Restricts resource loading
  • Strict-Transport-Security - HSTS in production

4. Infrastructure Security

Docker

  • Non-root user (nextjs, UID 1001)
  • Multi-stage builds (minimal production image)
  • No exposed database ports in production
  • Isolated Docker networks per stack

Database

  • Dual database architecture (app data vs user data)
  • Strong randomly-generated passwords (48 hex characters)
  • Connection strings not exposed externally
  • PostgreSQL 17 with healthchecks

5. Secrets Management

  • All secrets in environment variables (not in code)
  • Production secrets in docker-compose only (not in .env files in git)
  • NEXTAUTH_SECRET: 256-bit random
  • Database passwords: 192-bit random

Security Recommendations

Immediate (Should Do)

  1. Set up WAF (Web Application Firewall)
  2. Cloudflare Pro or similar
  3. Block common attack patterns
  4. Bot protection

  5. Enable Fail2ban or similar

  6. Monitor for brute force attempts
  7. Auto-ban suspicious IPs

  8. Database Backups

  9. Automated daily backups of postgres-users
  10. Off-site storage (S3, Backblaze B2)
  11. Test restore procedure

Medium-Term

  1. Implement CAPTCHA
  2. On sign-up/sign-in pages
  3. reCAPTCHA v3 or hCaptcha

  4. Add Audit Logging

  5. Log authentication attempts
  6. Log admin actions
  7. Log API abuse

  8. Set up Monitoring

  9. Uptime monitoring (Uptime Kuma)
  10. Performance monitoring

Long-Term

  1. SOC 2 Compliance
  2. If handling enterprise customers
  3. Security policies documentation

  4. Penetration Testing

  5. Annual third-party security audit
  6. Bug bounty program

  7. Security.txt

  8. Add /.well-known/security.txt
  9. Vulnerability disclosure policy

Known Vulnerabilities

Dependencies (as of build)

  • Run npm audit regularly
  • Auto-update via Dependabot/Renovate

Mitigated Issues

  • CVE-2024-XXXXX (Next.js middleware bypass) - Fixed via update to 15.5.9+

Incident Response

If a breach is suspected:

  1. Rotate all secrets immediately
  2. Invalidate all sessions (truncate sessions table)
  3. Review audit logs
  4. Notify affected users if PII exposed
  5. Document timeline and actions

Contact

Security issues: security@lynxprompt.com (configure when available)


Compliance Considerations

GDPR

  • User data in dedicated database (easy to export/delete)
  • No tracking without consent
  • Privacy policy needed

Data Retention

  • Sessions: Auto-expire after 30 days
  • User data: Retained until account deletion
  • Logs: Configure retention policy

Last updated: 2025-12-21