This document describes the security features implemented in Little ISMS Helper, following OWASP Top 10 guidelines and Symfony best practices.
Implementation:
-
Voters for fine-grained access control:
DocumentVoter- Document access control with multi-tenancyAssetVoter- Asset access control with multi-tenancyRiskVoter- Risk access control with multi-tenancyIncidentVoter- Incident access control with multi-tenancyControlVoter- Control access control with multi-tenancyComplianceInheritanceVoter- Compliance inheritance access controlEntityVoter- Generic entity access controlPermissionVoter- Permission management access controlRoleVoter- Role management access controlTagVoter- Tag access controlUserVoter- User management access control
-
Authorization checks:
#[IsGranted('ROLE_USER')]on all controllers$this->denyAccessUnlessGranted('view', $entity)for resource-level permissions- Multi-tenancy support in all voters
Testing:
# Test voter permissions
bin/console debug:voter AssetVoterImplementation:
-
Enhanced Session Security (
config/packages/framework.yaml):cookie_secure: 'auto'- HTTPS only in productioncookie_httponly: true- Prevents JavaScript access to session cookie (XSS protection)cookie_samesite: 'lax'- CSRF protection (cookie sent with same-site and top-level navigation requests)gc_maxlifetime: 3600- Session lifetime: 1 hour
-
Session Fixation Protection (
config/packages/security.yaml):- Symfony automatically regenerates session ID on successful authentication (built-in protection)
invalidate_session: trueon logout - Completely invalidates session on logout
-
Remember Me Cookie Security:
secure: auto- HTTPS only in production, HTTP allowed in developmenthttponly: true- No JavaScript accesssamesite: 'lax'- CSRF protectionlifetime: 604800- 1 week maximum
-
TLS/HTTPS Enforcement:
- HSTS header with 6 months max-age
- Automatic HTTP to HTTPS upgrade in CSP policy
Implementation:
-
SQL Injection Prevention:
- Doctrine ORM with prepared statements
- Raw SQL limited to backup/restore operations (SET FOREIGN_KEY_CHECKS, batch inserts)
-
XSS Prevention:
- Twig auto-escaping enabled (
autoescape: 'html') - CSP headers in production
InputValidationServicefor additional sanitization
- Twig auto-escaping enabled (
-
File Upload Injection:
FileUploadSecurityService:- MIME type validation (server-side via finfo)
- Magic byte verification
- Extension whitelist
- File size limits (10MB)
- Safe filename generation
-
Email Header Injection:
EmailNotificationService::sanitizeEmailSubject()- Removes control characters from email subjects
-
CSV/Excel Formula Injection:
ExcelExportService::sanitizeFormulaInjection()- Prefixes dangerous characters with single quote
-
Path Traversal:
DocumentController::download()with realpath validation- Filename sanitization
Implementation:
- Rate limiting for brute force prevention:
- Login: 5 attempts per 15 minutes
- API: 100 requests per minute
- Password reset: 3 attempts per hour
- Document upload: 20 uploads per hour
- Security event logging for monitoring
Implementation:
-
Security headers (
SecurityHeadersSubscriber, production only):Content-Security-PolicyX-Content-Type-Options: nosniffX-Frame-Options: SAMEORIGINStrict-Transport-Security(HSTS)Permissions-PolicyReferrer-Policy
-
Custom error pages (prevents information disclosure):
templates/bundles/TwigBundle/Exception/error{403,404,500}.html.twig
-
Production configuration:
- Session security hardening
- Error page customization
Recommendations:
# Regular dependency updates
composer update
composer audit
# Check for security advisories
symfony check:securityImplementation:
-
Login Rate Limiting (
config/packages/rate_limiter.yaml):- 5 attempts per 15 minutes
- Automatic 429 responses when limit exceeded
- IP-based tracking
-
Session Security (see A02 above):
- 1-hour session lifetime with garbage collection
- Secure, HttpOnly, SameSite=lax cookies
- Session fixation protection (automatic session regeneration on login)
- Session invalidation on logout
-
Password Security:
- Automatic bcrypt/argon2 hashing
- High cost factor for production
- Password hashing algorithm: auto (uses best available)
-
CSRF Protection:
- Enabled on all forms (
enable_csrf: true) - SameSite cookie attribute (
lax) - Token validation on form submissions
- Enabled on all forms (
Recommendations:
- Implement progressive account lockout after failed attempts
- Add password breach detection (HaveIBeenPwned API)
Recommendations:
- Implement Subresource Integrity (SRI) for CDN resources
- Add code signing for deployments
- Implement file integrity monitoring
Implementation:
-
SecurityEventLoggerservice:- Login success/failure
- Logout events
- Access denied (authorization failures)
- File upload success/failure
- Data modifications (CREATE, UPDATE, DELETE)
- Rate limit hits
- Suspicious activity
-
SecurityEventSubscriber:- Automatic logging for authentication events
- Exception logging
Usage:
// In controllers
$this->securityLogger->logFileUpload($filename, $mimeType, $size, $success);
$this->securityLogger->logDataChange('Asset', $id, 'UPDATE', $changes);
$this->securityLogger->logAccessDenied($resource, $action, $user);Log Location:
- Development:
var/log/dev.log - Production:
var/log/prod.log
Implementation:
- PDF generation:
isRemoteEnabled: false(prevents SSRF) - URL validation in
InputValidationService
Comprehensive file upload security:
// Validate file upload
$this->fileUploadSecurity->validateUploadedFile($file);
// Generate safe filename
$safeFilename = $this->fileUploadSecurity->generateSafeFilename($file);Features:
- MIME type validation (server-side)
- Magic byte verification
- Extension whitelist
- File size limits
- Safe filename generation
Centralized security event logging:
// Log events
$this->securityLogger->logLoginSuccess($user);
$this->securityLogger->logAccessDenied($resource, $action, $user);
$this->securityLogger->logFileUpload($filename, $mimeType, $size, $success);
$this->securityLogger->logSuspiciousActivity($description, $details);Input validation and sanitization:
// Validate and sanitize
$email = $this->inputValidation->validateEmail($input);
$int = $this->inputValidation->validateInteger($input);
$safeFilename = $this->inputValidation->sanitizeFilename($filename);
$safeHtml = $this->inputValidation->sanitizeHtml($html);
// Detect attacks
if ($this->inputValidation->detectXssPatterns($input)) {
// Log and reject
}All security headers are automatically applied in production environment:
- CSP: Restricts resource loading
- HSTS: Forces HTTPS (6 months)
- X-Frame-Options: Prevents clickjacking
- X-Content-Type-Options: Prevents MIME sniffing
- Permissions-Policy: Restricts browser features
- File Upload:
# Try uploading malicious files
curl -F "file=@malicious.php.jpg" http://localhost/document/new- Access Control:
# Try accessing other tenant's resources
curl -H "Cookie: PHPSESSID=..." http://localhost/asset/1- Rate Limiting:
# Try brute forcing login
for i in {1..10}; do curl -X POST http://localhost/login; done# Run security audit
composer audit
# Check for vulnerabilities
symfony check:security
# Run tests with coverage
php bin/phpunit --coverage-html coverage/Before deploying to production:
- Enable HTTPS
- Configure proper session storage (Redis/Memcached)
- Set up log rotation
- Configure monitoring and alerting
- Test all security headers
- Verify error pages
- Test file upload restrictions
- Verify rate limiting works
- Test access control for all resources
- Enable security event logging monitoring
If a security incident is detected:
- Check logs:
tail -f var/log/prod.log | grep SECURITY- Identify affected users:
SELECT * FROM audit_log WHERE created_at > 'incident_time';- Block attacker:
# config/packages/rate_limiter.yaml
# Reduce limits temporarily- Review security events:
grep "SUSPICIOUS_ACTIVITY\|ACCESS_DENIED" var/log/prod.logPriority improvements:
- ✅ Multi-Factor Authentication (MFA) - IMPLEMENTED
- ✅ Password complexity requirements - IMPLEMENTED (PasswordPolicyResolver)
- Account lockout mechanism
- IP whitelisting for admin panel
- API authentication (JWT/OAuth)
- ✅ Enhanced audit logging (database) - IMPLEMENTED
- Real-time security monitoring
- Automated vulnerability scanning