inveniosoftware / inveniosoftware/invenio

docs: securing your instance

Open
#3,906 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
663
Forks
295
PR merge metrics
No merged PRs in 30d

Description

General section to describe how to secure your Invenio instance

- Securing your installation
- APP_ALLOWED_HOSTS / SECRET KEY
- SSL Ciphers
- Keeping packages up-to-date
- Talisman: Content Security Policy
- Max file size uploads / quotas.
- Serving user uploaded files
- Authentication: Sessions, API, OAuth.
- Session protection
- XSS/CSRF protection
- Rate limiting.
- Backup and recovery
- Encryption

Contributor guide

Open the contributing guide

Research direction

No files, tests, or documentation entry point is named. First locate the existing documentation structure and relevant Invenio/Flask security guidance, then scope the listed topics into a coherent guide. Done means the security topics in the issue are covered with actionable guidance for an Invenio instance.

Written by the indexing model from the issue text.

Assessment

Tech stack
flask, python
Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.