Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

docs: securing your instance #3906

Open
lnielsen opened this issue Dec 10, 2018 · 0 comments
Open

docs: securing your instance #3906

lnielsen opened this issue Dec 10, 2018 · 0 comments

Comments

@lnielsen
Copy link
Member

lnielsen commented Dec 10, 2018

General section to describe how to secure your Invenio instance

  • Securing your installation
    • APP_ALLOWED_HOSTS / SECRET KEY
    • SSL Ciphers
    • Keeping packages up-to-date
    • Talisman: Content Security Policy
    • Max file size uploads / quotas.
    • Serving user uploaded files
  • Authentication: Sessions, API, OAuth.
  • Session protection
  • XSS/CSRF protection
  • Rate limiting.
  • Backup and recovery
  • Encryption
@lnielsen lnielsen assigned ntarocco and unassigned ntarocco Nov 11, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants