Security is not a package installed at the end. It is a chain of explicit decisions across every boundary where data, identity, files, money, or operational access can change state.
امنیت پکیجی نیست که در پایان نصب شود؛ زنجیرهای از تصمیمهای صریح در تمام مرزهایی است که داده، هویت، فایل، پول یا دسترسی عملیاتی میتواند تغییر وضعیت دهد.
Start with boundaries, not checklistsاز مرزها شروع کنید، نه از چکلیست
A useful threat model begins with a map of trust boundaries: browser to application, public route to authenticated route, user to role, application to storage, queue to worker, and deployment operator to production. For every boundary, write down what enters, who is allowed to trigger it, what changes, and how the decision is recorded.
مدل تهدید مفید با نقشهی مرزهای اعتماد آغاز میشود: مرورگر تا اپلیکیشن، مسیر عمومی تا مسیر احراز هویتشده، کاربر تا نقش، اپلیکیشن تا فضای ذخیرهسازی، صف تا worker و اپراتور انتشار تا production. برای هر مرز مشخص کنید چه چیزی وارد میشود، چه کسی مجاز به فعالکردن آن است، چه تغییری رخ میدهد و تصمیم چگونه ثبت میشود.
This changes security reviews from vague questions into testable claims. Instead of asking whether a project is secure, ask whether a customer can read another customer’s invoice, whether a forged webhook can change payment state, or whether an uploaded SVG can execute in an administrator’s browser.
این نگاه، بازبینی امنیت را از پرسشهای مبهم به ادعاهای قابلآزمایش تبدیل میکند. بهجای اینکه بپرسید پروژه امن است یا نه، بپرسید آیا یک مشتری میتواند فاکتور مشتری دیگر را بخواند، webhook جعلی وضعیت پرداخت را تغییر دهد یا SVG آپلودشده در مرورگر مدیر اجرا شود.
Authentication proves identity; authorization proves permissionاحراز هویت، هویت را ثابت میکند؛ مجوز، اجازه را
Laravel makes authentication approachable, but a valid session is not permission to perform every action. Policies and gates should express ownership, role, tenant, and resource state on the server. Hiding a button in the interface improves clarity; it does not create a security boundary.
Laravel احراز هویت را ساده میکند، اما session معتبر به معنی اجازه برای هر عملیات نیست. Policy و Gate باید مالکیت، نقش، tenant و وضعیت منبع را در سرور بیان کنند. پنهانکردن یک دکمه رابط را روشنتر میکند، اما مرز امنیتی نمیسازد.
Sensitive actions deserve fresh confirmation, narrow rate limits, predictable session invalidation, and an audit record. Account recovery should be treated as an authentication flow in its own right: tokens expire, old links become useless, responses avoid revealing whether an account exists, and privileged sessions can be revoked.
عملیات حساس به تأیید تازه، rate limit محدود، ابطال قابلپیشبینی session و سابقه ممیزی نیاز دارند. بازیابی حساب یک جریان احراز هویت مستقل است: توکنها منقضی میشوند، لینکهای قدیمی بیاثر میمانند، پاسخها وجود حساب را افشا نمیکنند و sessionهای دارای دسترسی بالا قابل ابطالاند.
Treat files and integrations as hostile inputبا فایلها و یکپارچهسازیها مثل ورودی غیرقابلاعتماد رفتار کنید
Validation should constrain shape, size, type, range, and business meaning. File uploads need generated names, storage outside executable paths, server-side MIME inspection, strict size limits, and delivery headers that prevent interpretation as active content. Never trust the extension supplied by the client.
اعتبارسنجی باید شکل، اندازه، نوع، بازه و معنای کسبوکاری داده را محدود کند. آپلود فایل به نام تولیدشده، ذخیره خارج از مسیر اجرایی، بررسی MIME در سرور، محدودیت حجم و هدر تحویل نیاز دارد تا محتوا بهصورت فعال تفسیر نشود. هرگز به پسوندی که کلاینت میفرستد اعتماد نکنید.
Webhooks, imports, and background jobs are also input surfaces. Verify signatures before parsing side effects, make handlers idempotent, cap retries, and retain enough correlation data to reconstruct what happened without logging secrets. A queue separates time; it does not remove authorization or validation requirements.
Webhook، import و job پسزمینه هم سطح ورودیاند. پیش از ایجاد اثر جانبی امضا را بررسی کنید، handler را idempotent بسازید، retry را محدود کنید و بدون ثبت اسرار، دادهی همبستگی کافی برای بازسازی رخداد نگه دارید. صف فقط زمان را جدا میکند؛ نیاز به مجوز و اعتبارسنجی را حذف نمیکند.
Operational security is product architectureامنیت عملیاتی بخشی از معماری محصول است
Secrets belong in environment-specific secret stores, not source control, build output, logs, screenshots, or browser-delivered JavaScript. Production should run with debug disabled, minimal filesystem permissions, a dedicated service account, TLS, controlled outbound access, and dependencies updated through a reviewed process.
اسرار باید در مخزن مخصوص هر محیط نگهداری شوند، نه در source control، خروجی build، log، screenshot یا JavaScript تحویلی به مرورگر. production باید با debug خاموش، حداقل مجوز فایل، حساب سرویس اختصاصی، TLS، دسترسی خروجی کنترلشده و فرایند بازبینیشدهی بهروزرسانی وابستگیها اجرا شود.
Backups are only evidence of resilience after a restore test. Record recovery objectives, encrypt copies, separate credentials from the primary host, and regularly verify that database, user files, and configuration can be reconstructed together. Monitoring should alert on outcomes—failed logins, permission denials, queue exhaustion, backup age—not just server uptime.
بکاپ فقط بعد از آزمون restore نشانهی تابآوری است. اهداف بازیابی را ثبت کنید، نسخهها را رمزگذاری کنید، اعتبارنامهها را از میزبان اصلی جدا نگه دارید و مرتباً بازسازی همزمان دیتابیس، فایل کاربر و تنظیمات را بیازمایید. پایش باید روی نتیجهها هشدار دهد—ورود ناموفق، رد مجوز، اشباع صف و عمر بکاپ—نه فقط روشنبودن سرور.
A release gate the team can actually useدروازه انتشار قابلاستفاده برای تیم
The best baseline is short enough to run on every release and specific enough to fail. Automate framework tests, static checks, dependency review, migration safety, secret scanning, and representative authorization tests. Then add a human gate for backup freshness, rollback readiness, infrastructure health, and live verification of the paths that carry the most risk.
بهترین خط مبنا آنقدر کوتاه است که در هر انتشار اجرا شود و آنقدر دقیق است که بتواند شکست بخورد. تستهای framework، بررسی ایستا، مرور وابستگی، ایمنی migration، جستوجوی secret و تستهای نمایندهی مجوز را خودکار کنید. سپس دروازه انسانی برای تازگی بکاپ، آمادگی rollback، سلامت زیرساخت و راستیآزمایی زندهی مسیرهای پرریسک اضافه کنید.
- Server-side policy tests cover ownership and rolesتستهای policy در سرور، مالکیت و نقشها را پوشش میدهند
- Uploads are non-executable, bounded, and inspectedآپلودها غیرقابلاجرا، محدود و بررسیشدهاند
- Secrets are absent from source, logs, and artifactssecretها در source، log و artifact وجود ندارند
- Backup, rollback, health, and live paths are verifiedبکاپ، rollback، سلامت و مسیرهای زنده تأیید شدهاند
