feat: improve data export security#1676
Conversation
|
@sakshiwankhade026-coder is attempting to deploy a commit to the PRIYANSHU DOSHI's projects Team on Vercel. A member of the Team first needs to authorize it. |
GSSoC Label Checklist 🏷️@Priyanshu-byte-coder — please apply the appropriate labels before merging: Difficulty (pick one):
Quality (optional):
Validation (required to score):
|
There was a problem hiding this comment.
Thanks for your first PR on DevTrack! 🎉
A maintainer will review it within 48 hours. While you wait:
- Make sure CI is passing (type-check + lint)
- Double-check the PR description is filled out and the issue is linked
- Feel free to ask questions in Discussions if you need help
If you find DevTrack useful, a ⭐ star on the repo is always appreciated — it helps the project grow and attract more contributors!
3c19df5
into
Priyanshu-byte-coder:main
|
🎉 Merged! Thanks for contributing to DevTrack. If the project has been useful to you, a ⭐ star on the repo is the easiest way to support it — it helps DevTrack get discovered by more developers. Keep an eye on open issues for your next contribution! |
Summary
Improves security for the user data export endpoint by adding audit logging, export rate limiting, and sensitive data redaction.
Closes #1612
Type of Change
Changes Made
data_export_auditHow to Test
GET /api/user/data-export429 Too Many RequestsDELETEDatabase Changes
Added new migration:
create_data_export_auditScreenshots (if UI change)
N/A
Checklist
npm run lintpasses locallynpm run buildpasses locallyAdditional Notes
The implementation introduces a dedicated audit table used for both export tracking and rate limiting. Existing authentication and authorization behavior remains unchanged.