Files
geointel/docs/18-ultra-prep/SECURITY_AND_SECRET_HANDLING.md
T
Jens faeb58ef6d
GeoIntel release gates / Compile, test, contracts and builds (push) Successful in 1m49s
GeoIntel release gates / Python and npm vulnerability policy (push) Successful in 21s
GeoIntel release gates / Production AI image, SBOM and container scan (push) Successful in 5m39s
GeoIntel release gates / Deploy exact gated revision to Unraid (push) Failing after 58m43s
Initial public release
2026-08-31 21:56:53 +02:00

795 B

Security and Secret Handling

Secrets

Never commit API keys, tokens, model credentials, STAC credentials, database passwords, or private URLs.

Environment Variables

All secrets must be loaded from .env or deployment environment.

File Upload Safety

  • limit accepted extensions;
  • validate MIME/type where possible;
  • store uploads outside source directories;
  • generate server-side filenames;
  • never execute uploaded files;
  • reject path traversal.

External Connectors

  • log endpoint names but not credentials;
  • timeout external requests;
  • cache responses where appropriate;
  • show connector status in UI.

AI/Model Safety

  • model files must be treated as artifacts;
  • do not auto-download arbitrary executable code;
  • keep model registry metadata separate from weights.