# Security Review

Date: 2026-07-15

Status: PARTIAL

## Findings

| Control | Status | Evidence |
|---|---|---|
| No raw photographs in logs | PARTIAL | Policy documented; runtime log review pending. |
| No tokens/secrets in frontend bundles | PARTIAL | `.env.example` uses placeholders; full bundle scan pending. |
| Content Security Policy | PARTIAL | Apache config sets CSP; header smoke via runtime config done, browser policy audit pending. |
| Referrer policy | PASS | Apache and JSON responses set policy. |
| Permissions policy | PASS | Camera/microphone constrained to self in Apache/JSON responses. |
| HSTS | BLOCKED | Requires HTTPS production endpoint. |
| Secure/HttpOnly/SameSite cookies | PARTIAL | PHP production ini sets HttpOnly/SameSite; runtime session test pending. |
| CSRF protection | BLOCKED | Not yet verified through runtime HTTP tests. |
| Admin MFA-ready integration | PARTIAL | Admin token scaffold exists; production MFA provider unresolved. |
| Rate limiting | BLOCKED | Join-token and mutation rate limiting need runtime implementation verification. |
| Upload MIME/content validation | PARTIAL | Successful generated PNG fixture validated; broader fixture matrix pending. |
| Image decode/re-encode | PARTIAL | Generated PNG fixture re-encoded to WebP; JPEG/WebP/corrupt/large/EXIF matrix pending. |
| Path traversal protection | PARTIAL | Asset paths sanitize wedding IDs; runtime tests pending. |
| SQL injection protection | BLOCKED | File-database scaffold remains; MySQL repository layer pending/runtime blocked. |
| XSS-safe rendering | PARTIAL | Vanilla DOM rendering mostly textContent; Playwright/browser audit pending. |
| WebSocket origin validation | PARTIAL | Token auth exists; origin allowlist verification pending. |
| Internal realtime publication token | PASS | Gateway requires `x-internal-realtime-token` for `/internal/publish`; public `/publish` rejects. |
| Join-token replay prevention | PARTIAL | Service scaffold and migration exist; MySQL runtime test pending. |

## Dependency Scans

| Scan | Status | Evidence |
|---|---|---|
| npm audit | PASS | `npm audit --audit-level=high` found 0 vulnerabilities. |
| Composer audit | PASS | `composer audit` found no advisories. |

## Logging Rules

Do not log raw photographs, session credentials, join tokens, entitlement tokens, admin secrets, or internal realtime publication tokens. Join audits must store token hashes only.
