Security Infrastructure Skill
Infrastructure security, headers, encryption, and compliance patterns.
Quick Reference
Security Headers
| Header |
Purpose |
Value |
| Content-Security-Policy |
XSS prevention |
Restrict sources |
| X-Frame-Options |
Clickjacking |
DENY |
| Strict-Transport-Security |
Force HTTPS |
max-age=31536000 |
| X-Content-Type-Options |
MIME sniffing |
nosniff |
| Referrer-Policy |
Leak prevention |
strict-origin |
Helmet.js Configuration
import helmet from 'helmet';
app.use(helmet({
contentSecurityPolicy: {
directives: {
defaultSrc: ["'self'"],
scriptSrc: ["'self'"],
styleSrc: ["'self'", "'unsafe-inline'"],
imgSrc: ["'self'", "data:", "https:"],
objectSrc: ["'none'"],
frameAncestors: ["'none'"],
},
},
hsts: { maxAge: 31536000, includeSubDomains: true },
}));
Encryption (AES-256-GCM)
import crypto from 'crypto';
function encrypt(plaintext: string, key: Buffer): EncryptedData {
const iv = crypto.randomBytes(12);
const cipher = crypto.createCipheriv('aes-256-gcm', key, iv);
let ciphertext = cipher.update(plaintext, 'utf8', 'base64');
ciphertext += cipher.final('base64');
return {
ciphertext,
iv: iv.toString('base64'),
authTag: cipher.getAuthTag().toString('base64'),
};
}
function decrypt(data: EncryptedData, key: Buffer): string {
const decipher = crypto.createDecipheriv(
'aes-256-gcm',
key,
Buffer.from(data.iv, 'base64')
);
decipher.setAuthTag(Buffer.from(data.authTag, 'base64'));
let plaintext = decipher.update(data.ciphertext, 'base64', 'utf8');
plaintext += decipher.final('utf8');
return plaintext;
}
Secrets Management
// Environment variables (basic)
const apiKey = process.env.API_KEY;
// AWS Secrets Manager
import { SecretsManager } from '@aws-sdk/client-secrets-manager';
const client = new SecretsManager({ region: 'us-east-1' });
const secret = await client.getSecretValue({ SecretId: 'my-secret' });
// HashiCorp Vault
import Vault from 'node-vault';
const vault = Vault({ endpoint: process.env.VAULT_ADDR });
const { data } = await vault.read('secret/data/myapp');
CORS Configuration
import cors from 'cors';
app.use(cors({
origin: ['https://app.example.com'],
methods: ['GET', 'POST', 'PUT', 'DELETE'],
allowedHeaders: ['Content-Type', 'Authorization'],
credentials: true,
maxAge: 86400,
}));
Compliance Checklist
GDPR Requirements
PCI-DSS Requirements
F5 Quality Gates
| Gate |
Requirement |
| G4 |
Security audit completed |
| G5 |
Production hardening verified |
| G5 |
Compliance checklist passed |
1---2name: security-infra3description: Infrastructure security, headers, encryption, and compliance. Use when: (1) Configuring security headers (CSP, CORS, HSTS), (2) Setting up HTTPS/TLS, (3) Data encryption at rest/transit, (4) Implementing compliance (GDPR, PCI-DSS), (5) Secrets management. Auto-detects: helmet, csp, cors, hsts, https, tls, ssl, encrypt, gdpr, pci-dss, compliance, secret, vault, kms4---5
6# Security Infrastructure Skill
7
8Infrastructure security, headers, encryption, and compliance patterns.
9
10## Quick Reference
11
12### Security Headers
13
14| Header | Purpose | Value |
15|--------|---------|-------|
16| Content-Security-Policy | XSS prevention | Restrict sources |
17| X-Frame-Options | Clickjacking | DENY |
18| Strict-Transport-Security | Force HTTPS | max-age=31536000 |
19| X-Content-Type-Options | MIME sniffing | nosniff |
20| Referrer-Policy | Leak prevention | strict-origin |
21
22## Helmet.js Configuration
23
24```typescript
25import helmet from 'helmet';
26
27app.use(helmet({
28 contentSecurityPolicy: {
29 directives: {
30 defaultSrc: ["'self'"],
31 scriptSrc: ["'self'"],
32 styleSrc: ["'self'", "'unsafe-inline'"],
33 imgSrc: ["'self'", "data:", "https:"],
34 objectSrc: ["'none'"],
35 frameAncestors: ["'none'"],
36 },
37 },
38 hsts: { maxAge: 31536000, includeSubDomains: true },
39}));
40```
41
42## Encryption (AES-256-GCM)
43
44```typescript
45import crypto from 'crypto';
46
47function encrypt(plaintext: string, key: Buffer): EncryptedData {
48 const iv = crypto.randomBytes(12);
49 const cipher = crypto.createCipheriv('aes-256-gcm', key, iv);
50
51 let ciphertext = cipher.update(plaintext, 'utf8', 'base64');
52 ciphertext += cipher.final('base64');
53
54 return {
55 ciphertext,
56 iv: iv.toString('base64'),
57 authTag: cipher.getAuthTag().toString('base64'),
58 };
59}
60
61function decrypt(data: EncryptedData, key: Buffer): string {
62 const decipher = crypto.createDecipheriv(
63 'aes-256-gcm',
64 key,
65 Buffer.from(data.iv, 'base64')
66 );
67 decipher.setAuthTag(Buffer.from(data.authTag, 'base64'));
68
69 let plaintext = decipher.update(data.ciphertext, 'base64', 'utf8');
70 plaintext += decipher.final('utf8');
71
72 return plaintext;
73}
74```
75
76## Secrets Management
77
78```typescript
79// Environment variables (basic)
80const apiKey = process.env.API_KEY;
81
82// AWS Secrets Manager
83import { SecretsManager } from '@aws-sdk/client-secrets-manager';
84const client = new SecretsManager({ region: 'us-east-1' });
85const secret = await client.getSecretValue({ SecretId: 'my-secret' });
86
87// HashiCorp Vault
88import Vault from 'node-vault';
89const vault = Vault({ endpoint: process.env.VAULT_ADDR });
90const { data } = await vault.read('secret/data/myapp');
91```
92
93## CORS Configuration
94
95```typescript
96import cors from 'cors';
97
98app.use(cors({
99 origin: ['https://app.example.com'],
100 methods: ['GET', 'POST', 'PUT', 'DELETE'],
101 allowedHeaders: ['Content-Type', 'Authorization'],
102 credentials: true,
103 maxAge: 86400,
104}));
105```
106
107## Compliance Checklist
108
109### GDPR Requirements
110- [ ] Data minimization - collect only necessary data
111- [ ] Consent management - explicit opt-in
112- [ ] Right to erasure - delete user data on request
113- [ ] Data portability - export user data
114- [ ] Breach notification - 72-hour window
115
116### PCI-DSS Requirements
117- [ ] Encrypt cardholder data at rest
118- [ ] Use TLS 1.2+ for transmission
119- [ ] Implement strong access control
120- [ ] Regular security testing
121- [ ] Maintain security policy
122
123## F5 Quality Gates
124
125| Gate | Requirement |
126|------|-------------|
127| G4 | Security audit completed |
128| G5 | Production hardening verified |
129| G5 | Compliance checklist passed |