The following versions of ParkFinder are currently supported with security updates:
| Version | Supported |
|---|---|
| main | ✅ Yes |
Description: Hardcoded secret keys for JWT signing and admin creation bypass have been removed from the codebase.
Status: ✅ Fixed
What Changed:
JWT_SECRETreplaced withprocess.env.JWT_SECRETenvironment variableADMIN_SECRETreplaced withprocess.env.ADMIN_SECRETenvironment variable- Added startup validation to prevent server startup if required environment variables are missing
Affected Files Modified:
server/controllers/auth.controller.js- Line 16 (admin secret check), Line 51 (JWT signing)server/middleware/auth.js- Line 16 (JWT verification)server/server.js- Lines 15-27 (Environment variable validation added).env.example- Created with documented required variables
Action Required:
- Update your
.envfile with secure random values forJWT_SECRETandADMIN_SECRET - Ensure
.envis in.gitignoreand never committed to version control - In production, set these variables through your hosting platform's environment configuration
The following environment variables are REQUIRED for secure operation:
| Variable | Purpose | Min Length |
|---|---|---|
JWT_SECRET |
Sign and verify JWT authentication tokens | 32 characters |
ADMIN_SECRET |
Validate admin account creation requests | 32 characters |
On Linux/Mac:
openssl rand -base64 32On Windows (PowerShell):
[System.Convert]::ToBase64String([System.Security.Cryptography.RNGCryptoServiceProvider]::new().GetBytes(32))-
Copy the template:
cp .env.example .env
-
Generate and add secure values:
# Generate JWT_SECRET openssl rand -base64 32 # Generate ADMIN_SECRET openssl rand -base64 32
-
Update
.envwith generated values and verify.envis in.gitignore -
Start the server - it validates all required environment variables at startup:
npm run dev
For Render, Vercel, or similar platforms:
- Do NOT include
.envfile in your repository - Set environment variables directly in the platform's dashboard:
- Navigate to Settings → Environment Variables
- Add
JWT_SECRETandADMIN_SECRETwith secure values
- The application validates these variables on startup and will fail with a clear error if missing
To report a security vulnerability in ParkFinder, please reach out via:
- 👤 Maintainer: imanchalsingh
- 💬 Contact the maintainer through any social links listed on the GitHub profile
Please do not open a public GitHub issue for security vulnerabilities.
- A clear description of the vulnerability
- Steps to reproduce the issue
- Affected versions or components
- Potential impact assessment
- Any suggested fix (optional but appreciated)
| Action | Timeframe |
|---|---|
| Acknowledgement of report | Within 48 hours |
| Status update | Within 7 days |
| Patch / fix release | Within 30 days |
We follow a responsible disclosure policy:
- Please report vulnerabilities privately before any public disclosure
- We request an embargo period of 30 days to investigate and patch the issue
- After a fix is released, you are welcome to publish your findings
- We will credit reporters in the patch notes unless anonymity is requested
- We deeply appreciate the efforts of security researchers 🙏