security: harden production configuration and routes
Run Tests on Branches / Detect Changes (push) Successful in 12s
Run Tests on Branches / Frontend Tests (push) Successful in 2m12s
Run Tests on Branches / Frontend Mobile Tests (push) Has been skipped
Run Tests on Branches / Parapharmacy API Tests (push) Successful in 2m2s
Run Tests on Branches / PIP Platform Tests (push) Has been skipped
Run Tests on Branches / Backend Tests (push) Successful in 2m8s

This commit is contained in:
Antoni Nuñez Romeu
2026-07-22 17:24:54 +02:00
parent f60af5f6b2
commit 849763896d
21 changed files with 638 additions and 68 deletions
@@ -1,3 +1,4 @@
from pydantic import model_validator
from pydantic_settings import BaseSettings, SettingsConfigDict
@@ -12,6 +13,7 @@ class Settings(BaseSettings):
APP_NAME: str = "PIP - Pharmacy Integration Platform"
APP_VERSION: str = "0.1.0"
DEBUG: bool = False
NODE_ENV: str = "development"
DATABASE_URL: str = "postgresql+asyncpg://pip:pip@localhost:5432/pip"
DATABASE_POOL_SIZE: int = 20
@@ -50,6 +52,23 @@ class Settings(BaseSettings):
HEALTH_CHECK_CACHE_TTL: int = 10
@model_validator(mode="after")
def validate_production_security(self):
if self.NODE_ENV.lower() != "production":
return self
if self.JWT_SECRET_KEY == "change-me-in-production":
raise ValueError("JWT_SECRET_KEY must be changed in production")
default_credentials = ("pip:pip@", "pip-secret")
if any(value in self.DATABASE_URL or value in self.RABBITMQ_URL for value in default_credentials):
raise ValueError("default database or broker credentials are not allowed in production")
if self.CORS_ALLOW_CREDENTIALS and "*" in self.CORS_ORIGINS:
raise ValueError("wildcard CORS_ORIGINS are not allowed with credentials in production")
return self
@property
def DATABASE_URL_SYNC(self) -> str:
return self.DATABASE_URL.replace("+asyncpg", "+psycopg2", 1)