Spaces:
Sleeping
Sleeping
File size: 7,769 Bytes
f907bb1 | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 | {\rtf1\ansi\deff0\nouicompat{\fonttbl{\f0\fnil\fcharset0 Calibri;}{\f1\fnil Calibri;}{\f2\fnil\fcharset1 Cambria Math;}}
{\*\generator Riched20 10.0.19041}{\*\mmathPr\mmathFont2\mwrapIndent1440 }\viewkind4\uc1
\pard\sa200\sl276\slmult1\f0\fs22\lang9 You are a Senior Software Architect, Senior Backend Engineer, Senior DevOps Engineer, and Senior Security Engineer.\par
\par
Analyze the entire existing codebase and implement all required improvements directly in the project without breaking any existing functionality.\par
\par
Project Goal:\par
Transform the current application into a Production-Ready SaaS foundation with strong security, scalability, maintainability, monitoring, and enterprise-grade architecture.\par
\par
========================\par
PHASE 1 \f1\emdash SECURITY HARDENING\par
============================\par
\par
1. CORS Security\par
\par
* Remove any wildcard or fully open CORS configuration.\par
* Allow requests only from approved frontend domains.\par
* Support environment-based domain configuration.\par
* Separate Development and Production configurations.\par
\par
2. Helmet Security\par
\par
* Install and configure Helmet.\par
* Enable all recommended security headers.\par
* Configure Content Security Policy properly.\par
\par
3. Rate Limiting\par
\par
* Implement express-rate-limit.\par
* Create separate limits for:\par
\par
* Login\par
* Register\par
* Password Reset\par
* API Requests\par
* Return proper error responses.\par
\par
4. Authentication Security\par
\par
* Audit JWT implementation.\par
* Improve token validation.\par
* Validate expiration handling.\par
* Protect against token abuse.\par
* Ensure secure secret management.\par
\par
5. Cookie Security\par
\par
* Use:\par
\par
* httpOnly\par
* secure\par
* sameSite=strict\par
* Environment-aware configuration.\par
\par
6. CSRF Protection\par
\par
* Implement CSRF protection for cookie-based authentication.\par
* Secure all sensitive endpoints.\par
\par
7. Input Validation\par
\par
* Ensure every endpoint uses Zod validation.\par
* Remove any unvalidated request body.\par
* Sanitize user input.\par
* Prevent injection attacks.\par
\par
8. File Upload Security\par
\par
* Validate MIME types.\par
* Validate file extensions.\par
* Validate file size.\par
* Block SVG uploads.\par
* Prevent malicious file execution.\par
* Implement upload scanning layer.\par
\par
9. Security Logging\par
\par
* Log:\par
\par
* Login attempts\par
* Failed authentication\par
* Permission violations\par
* Suspicious activity\par
\par
========================\par
PHASE 2 \emdash ROLE BASED ACCESS CONTROL\par
===================================\par
\par
Implement Enterprise RBAC.\par
\par
Roles:\par
\par
* Super Admin\par
* Admin\par
* Manager\par
* Staff\par
* User\par
\par
Requirements:\par
\par
* Permission matrix.\par
* Middleware:\par
authorize(...)\par
* Route protection.\par
* Page protection.\par
* API protection.\par
* Database-level role checks.\par
\par
Examples:\par
\par
* Only Super Admin can manage platform settings.\par
* Admin can manage organization resources.\par
* Staff can only access assigned resources.\par
* Users can only access their own data.\par
\par
========================\par
PHASE 3 \emdash MULTI TENANT ARCHITECTURE\par
===================================\par
\par
Convert architecture to true SaaS multi-tenancy.\par
\par
Requirements:\par
\par
1. Tenant Entity\par
\par
* Create Tenant model.\par
\par
2. Tenant Isolation\par
\par
* Every record belongs to tenant.\par
* Prevent cross-tenant access.\par
\par
3. Tenant Middleware\par
\par
* Automatically resolve tenant.\par
* Attach tenant context.\par
\par
4. Database Protection\par
\par
* Every query must be tenant-aware.\par
\par
5. Super Admin Bypass\par
\par
* Platform administrators can access all tenants.\par
\par
========================\par
PHASE 4 \emdash BACKEND ARCHITECTURE IMPROVEMENTS\par
===========================================\par
\par
Refactor into:\par
\par
Controller\par
\f2\u8595?\f0\par
Service\par
\f2\u8595?\f0\par
Repository\par
\f2\u8595?\f0\par
Prisma\par
\par
Requirements:\par
\par
* Controllers contain no business logic.\par
* Services contain business logic.\par
* Repositories handle database access.\par
* Shared abstractions.\par
* Dependency injection friendly structure.\par
\par
========================\par
PHASE 5 \f1\emdash OBSERVABILITY\par
=======================\par
\par
1. Logging\par
\par
* Implement Winston or Pino.\par
* Structured JSON logs.\par
* Environment aware.\par
\par
2. Error Tracking\par
\par
* Integrate Sentry.\par
* Capture exceptions.\par
* Capture API failures.\par
\par
3. Request Tracing\par
\par
* Track request lifecycle.\par
* Add correlation IDs.\par
\par
4. Health Checks\par
Create endpoints:\par
\par
/health\par
/health/database\par
/health/storage\par
\par
========================\par
PHASE 6 \emdash DATABASE IMPROVEMENTS\par
===============================\par
\par
Review Prisma schema.\par
\par
Requirements:\par
\par
* Add indexes.\par
* Add composite indexes.\par
* Add foreign key constraints.\par
* Optimize slow queries.\par
* Remove redundant fields.\par
* Improve relationships.\par
* Add soft delete support.\par
* Add audit fields:\par
\par
createdAt\par
updatedAt\par
createdBy\par
updatedBy\par
\par
========================\par
PHASE 7 \emdash TESTING\par
=================\par
\par
Implement:\par
\par
1. Unit Tests\par
\par
* Services\par
* Utilities\par
* Validation\par
\par
2. Integration Tests\par
\par
* API routes\par
* Database interactions\par
\par
3. Authentication Tests\par
\par
4. Authorization Tests\par
\par
Target:\par
Minimum 80% test coverage.\par
\par
========================\par
PHASE 8 \emdash DEVOPS\par
================\par
\par
1. Docker\par
\par
* Production Dockerfile\par
* Development Dockerfile\par
\par
2. Docker Compose\par
\par
* API\par
* PostgreSQL\par
* Redis\par
\par
3. Environment Validation\par
\par
* Validate env variables at startup.\par
\par
4. CI/CD\par
\par
* GitHub Actions\par
* Lint\par
* Test\par
* Build\par
* Deploy\par
\par
========================\par
PHASE 9 \emdash PERFORMANCE\par
=====================\par
\par
1. Redis Caching\par
2. Query Optimization\par
3. Pagination\par
4. Lazy Loading\par
5. Compression Middleware\par
6. API Response Optimization\par
\par
========================\par
PHASE 10 \emdash SAAS READINESS\par
=========================\par
\par
Implement missing SaaS features:\par
\par
1. Team Management\par
2. Invitation System\par
3. User Management\par
4. Subscription Ready Architecture\par
5. Billing Ready Architecture\par
6. Audit Logs\par
7. Activity History\par
8. Notification Infrastructure\par
9. Email Infrastructure\par
10. Feature Flag System\par
\par
========================\par
FINAL DELIVERABLE\par
=================\par
\par
Provide:\par
\par
1. Full code implementation.\par
2. Updated folder structure.\par
3. Security report.\par
4. Scalability report.\par
5. Production readiness report.\par
6. Database optimization report.\par
7. List of all modified files.\par
8. List of all new files.\par
9. Migration instructions.\par
10. Deployment instructions.\par
\par
Important:\par
Do not generate pseudo-code.\par
Do not leave TODO comments.\par
Implement production-quality code directly inside the existing project architecture.\par
Preserve existing functionality while applying all improvements.\f0\lang9\par
}
|