#227: hardening guide / VS-NfD reference configuration #275
Closed
fable-5
wants to merge 3 commits from
issue-227-hardening-guide into main
pull from: issue-227-hardening-guide
merge into: stwaidele:main
stwaidele:main
stwaidele:345-plugin-zip-license-texts
stwaidele:issue-339-markdown-table-paste
stwaidele:issue-338-tab-navigation
stwaidele:issue-337-merge-split
stwaidele:issue-336-delete-icons
stwaidele:issue-335-gap-cursor
stwaidele:feat/332-invitations
stwaidele:feat/331-admin-create-user
stwaidele:329-quota-override-cell-table-layout
stwaidele:324-325-self-hosting-guide-findings
stwaidele:323-document-title-instance-name
stwaidele:322-admin-settings-form-flat-keys
stwaidele:320-refresh-self-hosting-guide
stwaidele:fix/sort-key-test-timeout
stwaidele:issue-307-pond-branding
stwaidele:issue-305-pond-archive
stwaidele:issue-179-spa-lang
stwaidele:issue-306-instance-branding
stwaidele:issue-304-custom-font-ui
stwaidele:issue-303-fonts-dir-ownership
stwaidele:issue-303-custom-fonts
stwaidele:issue-301-settings-reflow
stwaidele:issue-302-pond-start-page
stwaidele:issue-300-icon-buttons
stwaidele:issue-296-remove-legacy-verify
stwaidele:issue-232-plugin-hash-pinning
stwaidele:adr-0019-0027-accepted
stwaidele:issue-246-vs-nfd-enforced
stwaidele:issue-245-vs-nfd-hidden
stwaidele:issue-244-vs-nfd-marked
stwaidele:issue-243-vs-nfd-mode
stwaidele:issue-221-offline-update
stwaidele:issue-220-isolated-run
stwaidele:issue-288-restore-partitioned
stwaidele:issue-219-offline-build
stwaidele:issue-218-registry-mirror
stwaidele:issue-217-claim-mapping
stwaidele:issue-216-local-auth-switch
stwaidele:issue-215-proxy-auth
stwaidele:issue-214-oidc
stwaidele:issue-225-read-trail-switch
stwaidele:issue-224-read-trail-storage
stwaidele:issue-223-read-trail-dedup
stwaidele:issue-222-read-trail
stwaidele:issue-228-security-documentation
stwaidele:issue-229-operations-manual
stwaidele:issue-230-grundschutz-mapping
stwaidele:issue-231-residual-risks
stwaidele:issue-213-upload-warning
stwaidele:issue-212-attachment-marking
stwaidele:issue-211-channel-marking
stwaidele:issue-210-zip-marking
stwaidele:issue-209-office-marking
stwaidele:issue-208-pdf-marking
stwaidele:issue-207-print-css
stwaidele:issue-206-web-classification-marking
stwaidele:issue-205-classification-inheritance
stwaidele:issue-204-page-classification
stwaidele:feat/203-image-digest-pinning
stwaidele:feat/201-audit-event-catalogue
stwaidele:feat/200-plugins-kill-switch
stwaidele:feat/199-attachment-integrity-hashes
stwaidele:feat/202-sbom-license-report
stwaidele:feat/236-pin-node-version
stwaidele:feat/235-page-links-purge-decision
stwaidele:feat/234-mail-outbox-retention
stwaidele:feat/233-conversion-job-payload-pruning
stwaidele:feat/198-env-verification
stwaidele:feat/197-security-headers
stwaidele:feat/196-audit-retention
stwaidele:feat/195-search-index-trash
stwaidele:feat/194-orphan-sweep
stwaidele:feat/193-pond-purge
stwaidele:feat/192-backup-allowlist
stwaidele:feat/191-feeds-switch
stwaidele:feat/190-session-timeouts
stwaidele:feat/189-csrf-fail-closed
stwaidele:feat/188-token-key-separation
stwaidele:docs/226-delimitation-statement
stwaidele:docs/vs-nfd-planning
stwaidele:feat/186-pond-accent
stwaidele:feat/184-theme-engine
stwaidele:feat/182-theme-toggle
stwaidele:feat/180-dark-mode
stwaidele:admin-actions-cell-align
stwaidele:admin-user-action-icons
stwaidele:a11y-mittel
stwaidele:a11y-aria
stwaidele:a11y-focus-lang
stwaidele:fix-160-plugin-block-editable
stwaidele:m23-chordpro
stwaidele:m22-aufgaben
stwaidele:m21-api-feeds
stwaidele:m20-ui-einbettung
stwaidele:k19-screenshot-svgfit
stwaidele:excalidraw-demo-docs
stwaidele:fix-137-3px
stwaidele:fix-137-nodeview
stwaidele:editor-autofocus
stwaidele:fix-137-checkbox
stwaidele:m17-m19-issues
3 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
| 0dc9789cb1 |
#227: hardening guide with the VS-NfD reference configuration
docs/vs-nfd/50-haertungsleitfaden.md: one adoptable profile — every entry with the exact switch name, value, default and the reason, split into instance settings (registration closed, api/mcp off, feeds off, plugins off, classification defaults vs_nfd + upload block, svg reject, minimal extension list) and deploy-level configuration (empty BACKUP_ALLOWED_TARGETS enforces backup-local-only outside Site-Admin reach; tightened session hours; SMTP deliberately unconfigured with the consequence stated honestly). auth.local.enabled is listed as the one pending row (#216) with its compensation until then; the guide states the binding updated-in-same-PR rule for every future switch. Includes an operator verification checklist (four unauthenticated 404 curls + readyz + admin spot checks). Cross-referenced from the delimitation statement (file names made concrete) and consumed by the Grundschutz mapping (#230). Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com> |
|||
| d641c5dc8a |
#229: operations manual (install, update, backup/restore, deletion, roles)
All checks were successful
docs/vs-nfd/70-betriebshandbuch.md: installation as run on the real stages (airgap variant explicitly pending #218-#221 with what already exists as groundwork), update/rollback incl. the no-down-migrations caveat, backup/restore with the ADR-0026 target allowlist and the rehearsed monthly restore drill (evidence: logs on #98), the full scheduler-job table (cadences verified against code), the deletion-and- destruction chapter built on the #228 copy list (per content type: what deletion reaches, what remains, immediate-destruction path, decommissioning), and role separation incl. the deliberate limits of a Site Admin and the honest note that Site Admin read-bypass makes the content/platform split non-absolute app-side. Every procedure carries its evidence level (erprobt / nicht geprobt / offen) — nothing claimed above what was actually executed. Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com> |
|||
| 1cf0458593 |
#228: security documentation (architecture, data flows, network plan)
docs/vs-nfd/60-sicherheitsdokumentation.md: component diagram with per- service purpose and privileges, network plan digit-exact against the deploy compose (127.0.0.1-only app bindings, internal-only data zone), data-flow diagrams (auth, realtime editing incl. LISTEN/NOTIFY and the 60s collab token, export via the pinned sidecars, backup incl. the ADR-0026 allowlist, and every read channel), named trust boundaries (reverse proxy, plugin sandbox, outbound SMTP/mirror), and the complete list of content copies — in-database, on-volume and outside the instance — that the deletion concept in #229 builds on. Mermaid only, German (assessor audience), with the maintained-in-same-PR rule stated. Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com> |