Implemented or scaffolded safeguards:
- HTTPS-only supported provider host allowlist.
- Rejection of playlist URLs containing credentials.
- No arbitrary server-side URL fetching.
- Zod validation for external input.
- PKCE helper generation.
- OAuth redirect path validation.
- Secure, same-site consent cookie configuration.
- Token encryption interface.
- AES-GCM token encryptor for Spotify refresh-token storage.
- Spotify OAuth state hashing, short expiration, and single-use consumption.
- Spotify token refresh and disconnect storage flow.
- Rate limiting abstraction.
- Secure response headers and CSP in
next.config.ts. - Correlation IDs on JSON responses.
- Secret redaction helper.
- Provider tokens separated in database schema.
Production work still required:
- Persist OAuth state hashes and enforce one-time consumption.
- Move OAuth state and token storage from in-memory foundation stores to Supabase.
- Add Supabase RLS policies for signed anonymous sessions.
- Store rate-limit counters in Supabase.
- Complete provider-specific OAuth callback validation.