Sensitive credentials
Wildberries tokens are encrypted with authenticated encryption and decrypted only inside backend requests. Browser responses receive masks and connection status, never raw tokens or encryption fields.
Authentication and sessions
New passwords use salted, memory-hard Argon2id hashes. Historical scrypt hashes are accepted only for compatibility and are upgraded after successful verification. Session identifiers and CSRF values are stored as hashes. Cookies are HttpOnly, SameSite Strict and Secure in production. Sessions have idle and absolute expiry and can be revoked.
Tenant isolation
Workspaces, seller accounts and memberships are checked server-side. Owner, Admin, Manager, Analyst and Viewer permissions are not trusted from browser input.
Operational controls
Health endpoints, structured request logs, protected metrics, PostgreSQL and Redis readiness checks, database backups, hash verification and incident runbooks are included.
Release boundary
Local tests and image builds do not equal an independent penetration test, public-cloud validation, legal certification or store approval. Those items remain explicit release blockers until evidence is supplied.
TONOYAN AI