eCom Learning Solutions / Developer toolsOpen source
Documentation/Security/OWASP security controls
08 / SECURITY

OWASP guidance in practice

The application includes controls aligned with the OWASP API Security Top 10 (2023) and REST Security Cheat Sheet. The source download includes a detailed implementation mapping in docs/owasp.md.

AreaImplemented controls
Authentication & accessKey validation before Studio tools load, API keys on protected PDF POST routes, constant-time digest comparison, required-key startup checks, and HTTPS enforcement by default.
Resource consumptionRequest/output budgets, page and asset limits, IP rate limits, bounded concurrency/queue, and cooperative rendering deadlines.
SSRF & unsafe contentRequest-owned image/font/PDF bytes; XHTML external resources and entities prohibited; imported PDF scripts, attachments, remote actions, and external streams rejected.
Frontend & responsesStrict CSP, safe DOM text insertion, framing protection, no browser key storage, bounded PDF previews, safe filenames, and sanitized error responses.
Configuration & inventoryConfigurable CORS (all origins by default, without cookies), host restrictions, explicit proxy trust, suppressed server/framework headers, OpenAPI, versioned routes, and corresponding source downloads.
Dependencies & secretsNuGet vulnerability auditing, build failure for known vulnerability warnings, source-file allowlists, and credential removal from bundled configuration.

Understand the current boundaries

Every configured key grants the same PDF permissions. Key issuance, expiry, rotation, revocation, and per-client quotas are not automated. Current traffic quotas apply per IP and per application process. The service generates a result for each call and has no stored customer documents or document retrieval endpoints.

File validation is not antivirus or a hard sandbox. PDF, image, and font decoders run inside the API process, and cancellation is cooperative. Operators should use isolated rendering with hard resource limits, gateway protection, and monitored security events for public workloads. Keep the runtime, proxy, operating system, and vendored browser libraries patched.

OWASP advises stronger authentication for sensitive or high-value resources. Configure appropriate identities and permissions for those deployments. Framework logging is present; a dedicated audit trail and alerting system still need to be configured or integrated.

Verification status
Security regression tests and browser checks exercise the implemented controls. An independent penetration test and a full OWASP ASVS assessment have not been completed.