Skip to content

Conductor_Audit_and_Update

movitto edited this page Jan 14, 2013 · 2 revisions

Conductor Audit and Update

Current Tasks In Progress

Integrating best practices gem in and starting to automate the verification of our application

Allocating the controllers & models for the next round of security work

Tasks on the table

Updating the remaining controllers based on the audit: settings, deployments, roles, realms, deployables, target/provider images )

Updating the remaining model classes based on the audit

Ensure user data & session is properly encrypted over https

Add functionality to Conductor:

Diff the codebase between the version audited and the current HEAD and audit the changes

Optional security features (not blockers for live deployment)

  • self-service / registration (? not necessarily needed as we can require authorization / manual signups)

Back to Hardening_the_app

Clone this wiki locally