Initial GeoIntel V1 foundation
This commit is contained in:
@@ -0,0 +1,26 @@
|
||||
# Security and Secret Handling
|
||||
|
||||
## Secrets
|
||||
Never commit API keys, tokens, model credentials, STAC credentials, database passwords, or private URLs.
|
||||
|
||||
## Environment Variables
|
||||
All secrets must be loaded from `.env` or deployment environment.
|
||||
|
||||
## File Upload Safety
|
||||
- limit accepted extensions;
|
||||
- validate MIME/type where possible;
|
||||
- store uploads outside source directories;
|
||||
- generate server-side filenames;
|
||||
- never execute uploaded files;
|
||||
- reject path traversal.
|
||||
|
||||
## External Connectors
|
||||
- log endpoint names but not credentials;
|
||||
- timeout external requests;
|
||||
- cache responses where appropriate;
|
||||
- show connector status in UI.
|
||||
|
||||
## AI/Model Safety
|
||||
- model files must be treated as artifacts;
|
||||
- do not auto-download arbitrary executable code;
|
||||
- keep model registry metadata separate from weights.
|
||||
Reference in New Issue
Block a user