No description
Find a file
goose ff185a60e4
All checks were successful
Lint and Build / format (pull_request) Successful in 38s
Lint and Build / clippy (pull_request) Successful in 1m40s
Lint and Build / build (pull_request) Successful in 3m46s
Lint and Build / test (pull_request) Successful in 4m0s
fix(security): enforce ownership on medication/appointment write paths (#12)
The update/delete handlers for medications and appointments took the
auth Claims but never used them — any authenticated user could update
or delete any other user's records by id (an IDOR). Same gap on
log_dose (could skew another's adherence stats) and get_adherence
(leaked dose history).

Fix: each affected handler now looks up the item first and confirms
user_id == claims.sub before mutating/returning. Mismatches return 404
(not 403) to avoid leaking the existence of other users' records.
Recipients of shared profiles remain read-only per the ADR — writes
stay owner-only.

Covered handlers:
- update_medication, delete_medication, log_dose, get_adherence
- update_appointment, delete_appointment

health_stats update/delete were already checking user_id == claims.sub
(unaffected).

New ownership_tests.rs: cross-user update/delete/log-dose/adherence all
404; the legitimate owner can still do all of the above.

Verification: cargo build/clippy (-D warnings)/fmt clean; existing
tests unaffected (they operate as the same user that created the data).

Closes #12.
2026-07-19 12:00:13 -03:00
.forgejo/workflows ci: drop host port mapping for Mongo service container 2026-07-18 21:02:46 -03:00
backend fix(security): enforce ownership on medication/appointment write paths (#12) 2026-07-19 12:00:13 -03:00
docs docs: decide multi-person ZK sharing ADR; reconcile jwt/encryption docs 2026-07-18 19:26:43 -03:00
scripts fix(backend): P1 — handler unwrap cleanup + rewrite integration tests 2026-06-27 14:26:39 -03:00
web feat: profile sharing via X25519 envelope (Phase B, #3) 2026-07-19 07:21:11 -03:00
.cursorrules docs: reconcile documentation with reality (P3) 2026-06-27 16:02:16 -03:00
.gitignore feat(auth): add per-account X25519 identity keypair (#3) 2026-07-18 20:00:01 -03:00
.gooserules docs: add AGENTS.md and document issue-driven workflow 2026-07-18 11:20:14 -03:00
AGENTS.md docs: add AGENTS.md and document issue-driven workflow 2026-07-18 11:20:14 -03:00
README.md fix(backend): P2 config & Docker consistency 2026-06-27 19:54:32 -03:00

Normogen

Normogen (Mapudungun for "Balanced Life") is an open-source health data platform for private, secure health data management.

📚 Documentation

All project documentation has been organized into the docs/ directory:

🚀 Quick Start

# Clone repository
git clone <forgejo-url> normogen
cd normogen/backend

# Setup configuration
cp .env.example .env
# Edit .env with your values

# Run with Docker Compose
docker compose up -d

# Check status (default port is 6500 via NORMOGEN_PORT; Solaria maps it to host 6800)
curl http://localhost:6500/health

📊 Current Status

  • Backend: Phase 2.x feature-complete (Rust + Axum + MongoDB), including drug interactions (Phase 2.8). Security-hardened: token-version validation, hashed refresh-token persistence, fail-fast config, real-IP audit logging. Deployed on Solaria.
  • Frontend: 🚧 Early (React + TypeScript) — Login/Register pages + API/store layer exist; router not yet wired.
  • Tests: 18 unit + 13 integration (auth + medication), CI-gated with MongoDB.
  • Deployment: Docker on Solaria (image built manually — CI can't run DinD on Forgejo).
  • See docs/product/STATUS.md for the full breakdown.

🗂️ Documentation Structure

docs/
├── product/          # Product definition, features, roadmap
├── implementation/   # Phase plans, specs, progress reports
├── testing/          # Test scripts and results
├── deployment/       # Deployment guides and scripts
├── development/      # Git workflow, CI/CD, development tools
└── archive/          # Historical documentation

📖 Full Documentation

See the Documentation Index for complete project documentation.


Last Updated: 2026-06-27