mozilla-services / pushbox

Durable Storage for Push
Mozilla Public License 2.0
6 stars 9 forks source link

Prod security review #6

Closed bbangert closed 5 years ago

bbangert commented 6 years ago

When pushbox is ready to go to prod, it needs a security review. Correlating privatesec-review issue:

jvehent commented 6 years ago

You might want to go through this, though I expect most of it will not apply to this project, so just cross it off or mark it as done.


Risk Management

Infrastructure

Development

Dual Sign Off

Logging

Security Headers

Security Features

Databases

Common issues

bbangert commented 6 years ago

This is blocked on pushbox being 'complete'.

jvehent commented 6 years ago

any update?

bbangert commented 6 years ago

I believe we are waiting till rustbox is ready, as that will be the final prod version, not the AWS serverless one.

rfk commented 5 years ago

@jrconlin what followup do we need on this issue now that things are ready for prod?

jrconlin commented 5 years ago

Going to go through the checklist this morning, then see about getting it scheduled for review. If you like, you can add it to any new FxA service review you're doing, or I can keep it separate.

jrconlin commented 5 years ago

Added draft RRA

jrconlin commented 5 years ago

Added Risk Record bug

jrconlin commented 5 years ago

Closing as complete. No additional actions requested by OpSec.