diff --git a/LICENSE b/LICENSE new file mode 100644 index 000000000..0bd0c21b1 --- /dev/null +++ b/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2026 小虾 SaaS + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 000000000..fa74c1685 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,87 @@ +# Security Policy + +## Supported Versions + +We release patches for security vulnerabilities in the following versions: + +| Version | Supported | +| ------- | ------------------ | +| 1.0.x | :white_check_mark: | +| < 1.0 | :x: | + +## Reporting a Vulnerability + +We take the security of 小虾 SaaS seriously. If you believe you have found a security vulnerability, please report it to us as described below. + +### Please do NOT: + +- Open a public GitHub issue about the vulnerability +- Discuss the vulnerability publicly (Twitter, blog posts, etc.) + +### Please DO: + +1. **Email us directly:** security@xiaoxia-saas.com +2. **Include the following information:** + - Type of vulnerability + - Full path to the source file(s) related to the vulnerability + - Location of the affected code (tag/branch/commit) + - Step-by-step instructions to reproduce the issue + - Proof-of-concept or exploit code (if possible) + - Impact of the vulnerability + +### What to expect: + +- We will acknowledge your email within 48 hours +- We will provide a more detailed response within 7 days +- We will work on a fix and release a patch ASAP +- We will credit you in the release notes (if you wish) + +## Security Best Practices + +When deploying 小虾 SaaS: + +1. **Change all default secrets:** + - `JWT_SECRET_KEY` (minimum 32 characters) + - Database passwords + - Redis passwords + +2. **Use HTTPS in production:** + - Configure SSL certificates + - Enable HTTPS redirect + +3. **Enable rate limiting:** + - Uncomment `RateLimitMiddleware` in production + - Configure appropriate limits + +4. **Regular updates:** + - Keep dependencies up to date + - Apply security patches promptly + +5. **Database security:** + - Use strong passwords + - Limit network access + - Enable SSL connections + +## Security Features + +小虾 SaaS includes: + +- ✅ bcrypt password hashing (cost=12) +- ✅ JWT token signing and validation +- ✅ SQL injection protection (parameterized queries) +- ✅ XSS protection (input validation) +- ✅ CORS configuration +- ✅ Rate limiting +- ✅ Session management + +## Disclosure Policy + +When we receive a security bug report, we will: + +1. Confirm the problem and determine affected versions +2. Audit code to find similar problems +3. Prepare fixes for all supported versions +4. Release patches as soon as possible +5. Publicly disclose the vulnerability + +Thank you for helping keep 小虾 SaaS and our users safe!