Secure production defaults 🔗

This reference applies to Sharaf 0.19.0 applications using sharaf-pac4j.

Concern Production baseline
Transport HTTPS only; redirect HTTP at the trusted proxy; enable HSTS after confirming every public subdomain supports HTTPS.
Public surface Protect all routes by default. Exclude only named public endpoints and static assets.
Browser session Secure, HttpOnly, SameSite=Strict, narrow path/domain, short idle expiry, absolute expiry, regenerated after login, destroyed at logout.
Session storage Use Redis or JDBC-backed SessionStore for replicas or restart-safe sessions. Do not use InMemorySessionStore in production.
API tokens Use a HeaderClient plus NoOpSessionStore; validate signature, expiry, issuer and audience where applicable; rotate signing keys.
Credentials Store bcrypt/Argon2 password hashes, rate-limit login, use generic login errors, never log passwords, tokens, cookies, or authorization headers.
OAuth/OIDC Exact registered HTTPS callback URL; validate provider metadata and tokens; store client secrets outside source control; allow-list post-login redirects.
Authorization Enforce roles with pac4j authorizers and enforce resource ownership in application code. Test denial paths.
CSRF Verify a session-bound token on every unsafe browser request; use Origin/Referer as defense in depth.
Response headers Enable DefaultMatchers.SECURITYHEADERS; add application-specific CSP, Strict-Transport-Security, Referrer-Policy, and Permissions-Policy at the proxy.
Proxy trust Only trust forwarded headers added by an owned proxy. Strip all client-supplied forwarded headers before proxying.
Request limits Bound request/upload size, timeout, and rate at the proxy and server adapter. Return 413 for oversized bodies.
Secrets Validate required secrets at startup; use a secret manager or deployment environment; redact values and rotate them on a schedule.
Verification Test authentication, authorization, CSRF, session regeneration/logout, headers, size limits, and external callback URLs through the deployed proxy.

Sharaf's pac4j handler currently writes SHARAF_SESSION cookies as Secure, HttpOnly, SameSite=Strict, path /, with a 30-minute maximum age. These are sensible browser defaults, but they do not make an HTTP deployment safe and do not replace CSRF validation or a persistent store.

For setup and deployment details, use the security guide.