Clear calculations. Better home decisions.Need help? support@myhomejankaari.com
Security

Security practices for accounts, content and website data

My Home Jankaari uses layered application controls and requires equally careful hosting and operational practices. This page describes the intended safeguards without claiming that any online system is risk-free.

01

Secure authentication and password storage

The PHP backend uses PHP's password hashing and verification functions. Plain-text passwords are never written to the database. Successful login creates a cryptographically random API token, while only its SHA-256 hash is retained server-side. Tokens expire and can be revoked at logout or after a password reset.

Production login endpoints should always run through HTTPS. Administrator passwords should be changed immediately after installation, kept unique and protected with a password manager.

02

Role-based access control

Member, Editor and Administrator are separate roles. Members access their own planning workspace. Editors manage blog drafts and published content, but cannot permanently delete articles. Administrators have full blog and user-management authority.

The PHP interface hides inaccessible actions for usability, while the PHP API repeats permission checks on the server. Server-side authorization is the control that protects data even if someone manually constructs a request.

03

Database and request protection

All database reads and writes use PDO prepared statements with emulated prepares disabled. Inputs are validated for type, length, format and allowed status values. Duplicate slugs and emails receive controlled errors instead of raw database output in production mode.

The API should connect through a database user with only the permissions required by this application. Remote database access should be restricted to the application server or a private network.

04

Safer image uploads

Blog images are limited to JPG, PNG and WebP, checked through server-side MIME detection and restricted to 2 MB. Stored filenames are random rather than based on user-supplied names. The upload directory must not execute PHP or other server-side scripts.

A production deployment can add image resizing, malware scanning, storage quotas and content moderation according to the site's risk profile.

05

Transport, headers and browser controls

Use a valid TLS certificate and redirect every HTTP request to HTTPS. Recommended production headers include a carefully tested Content Security Policy, HSTS, X-Content-Type-Options, Referrer-Policy and suitable frame restrictions.

The API allows cross-origin access only from the configured website origin. Broad wildcard CORS settings should not be used with authenticated production requests.

06

Backups, updates and monitoring

Security is an operating process, not a one-time code feature. Keep versioned database backups, test restoration, patch PHP, MySQL, Node and dependencies, review administrator access and watch logs for repeated failures or unusual write activity.

Backups should be encrypted, access-controlled and retained separately from the live server. A backup that has never been restored in a test should not be considered reliable.

07

Report a security concern

Send a concise report to support@myhomejankaari.com with the affected URL, observed behaviour, approximate time and safe reproduction steps. Do not access other people's information, disrupt the service or publicly expose sensitive details while a report is being investigated.

We aim to acknowledge responsible reports, preserve relevant logs, assess the impact and communicate appropriate remediation. Emergency response procedures should be finalized before public launch.