← Files Web App QA & Release CopilotARCHIVED FILE

skills/web-qa-release/references/web_security_privacy_release_checks.md

2.19 KB · Oct 4, 2026 · 12:36 UTC

↓ Download file

# Web Security and Privacy Release Checks

## Purpose

Use this file for pragmatic release-oriented security review.

Use current OWASP guidance when detailed verification is required.

# 1. Authentication

Check changes involving signup/login, password reset, MFA, sessions, account recovery, logout, and invalidation.

Verify failure paths as well as happy paths.

# 2. Authorization

Check:
- object/resource ownership;
- tenant boundaries;
- admin-only actions;
- server-side authorization;
- ID manipulation;
- role changes.

Hiding UI is not authorization.

# 3. Sessions/cookies

Review when relevant:
- Secure;
- HttpOnly;
- SameSite;
- lifetime/expiry;
- rotation;
- logout invalidation;
- cross-site flow requirements.

# 4. Input/output

Check for injection, XSS, unsafe HTML, SQL/command injection, path traversal, open redirect, SSRF, and unsafe deserialization.

Use framework-native safe APIs where available.

# 5. Uploads

Check type/size validation, storage location, content serving, executable content, filename/path handling, access control, and malware scanning when required.

# 6. Secrets

Check repository, frontend bundles, source maps, CI logs, environment files, error output, and browser storage.

Client-side secrets are not secrets.

# 7. Dependencies

If dependencies changed:
- inspect dependency diff;
- known vulnerabilities;
- unexpected transitive changes;
- package origin;
- lockfile.

Do not block solely on severity labels without context, but do not ignore critical known vulnerabilities.

# 8. Security headers

Depending on architecture, inspect CSP, HSTS, framing protections, content-type protections, referrer policy, and permissions policy.

Do not apply headers blindly if they break legitimate flows.

# 9. Privacy

Review personal data collected, purpose, retention, analytics/tracking, consent where applicable, deletion/export, logs, and third parties.

Minimize data collection.

# 10. Release classification

Use:
- **Block release** — confirmed material vulnerability/exposure.
- **Must verify** — security-critical behavior lacks sufficient evidence.
- **Follow-up** — hardening without material release risk.

Do not claim a release is “secure” based only on an automated scan.

SHA-256: 35e5ae4f8ebe3d14555bb7e52873fa072c2506c0c3348b1a8b8f2aedf6c3690b