Good Practices & Security
To maintain a high standard of code quality and protect user data, all contributions to the 180workspace Platform must adhere to the following security and coding practices.
1. API Security (Backend)
- Rate Limiting: The
express-rate-limitpackage is implemented globally (globalLimiter) and strictly on authentication routes (authLimiter) to prevent brute-force attacks. - Helmet: We use
helmetto automatically set secure HTTP headers (e.g., preventing clickjacking). - NoSQL Injection Prevention:
express-mongo-sanitizeis active to strip out keys containing$or.fromreq.body,req.query, andreq.params. - JWT Security: Tokens should never be logged. Ensure
JWT_SECRETis rotated periodically in production environments.
2. Observability & Error Tracking
- Sentry: We use
@sentry/nodeand@sentry/profiling-nodefor error tracking. Ensure you capture exceptions usingSentry.captureException(err)within catch blocks if they are not passed to the global error handler. - Logging: We use
morganfor HTTP request logging. Do not log sensitive user data (passwords, tokens, PII).
3. Coding Standards (Monorepo)
- Linting: We have centralized ESLint configurations (
packages/eslint-config). Runpnpm lintbefore pushing any code. - TypeScript: We strongly type all frontend code and shared packages. Use Zod for runtime schema validation, especially for API requests.
- DRY (Don't Repeat Yourself): If you find yourself duplicating UI elements in
admin-webanduser-web, extract the component to the@workspace/uipackage.
4. Frontend Performance
- Image Optimization: Always use the Next.js
<Image />component rather than standard<img>tags. - Caching: Leverage RTK Query's built-in caching for API requests. Do not manually implement
useEffectdata fetching unless absolutely necessary. - Lazy Loading: For heavy components (e.g., charts or rich text editors), use Next.js dynamic imports (
next/dynamic) to reduce the initial JavaScript payload.