3.0 KiB
3.0 KiB
description, applyTo
| description | applyTo |
|---|---|
| Security requirements for secrets management, input validation, permissions, and secure coding | **/*.cs, **/*.appxmanifest |
Security
These rules apply to every feature and change. They are not optional add-ons.
Rules
- Never hard-code secrets (API keys, passwords, connection strings) — use environment variables, Windows Credential Manager, or Azure Key Vault.
- Validate and sanitize all external input (user input, file content, network responses).
- Use
SecureStringorPasswordVaultfor sensitive data in memory when practical. - Follow the principle of least privilege — request only the permissions the app actually needs in
Package.appxmanifest. - Keep NuGet packages up to date — run
dotnet list package --outdatedregularly. - Enable code signing for published MSIX packages. Use the
winappCLI rather than hand-rollingsigntool:- Generate a development certificate matching the manifest publisher:
winapp cert generate --manifest .\Package.appxmanifest --install. - Inspect a cert before signing:
winapp cert info .\devcert.pfx. - Sign an existing file:
winapp sign .\MyApp.msix --cert .\devcert.pfx. - Build + sign in one step:
winapp pack .\bin\<Platform>\Release\<TFM>\win-<rid> --cert .\devcert.pfx. - Production releases must be signed by a trusted certificate authority -- never ship the development cert.
- Generate a development certificate matching the manifest publisher:
- When using
HttpClient, always validate TLS certificates and use HTTPS. - Never log sensitive data (PII, tokens, passwords).
Anti-patterns
- Storing secrets in
appsettings.jsoncommitted to source control. - Disabling TLS validation for debugging and forgetting to re-enable it.
- Using
Process.Startwith unsanitized user input. - Broad
try { } catch (Exception) { }that swallows errors silently without any logging.
Validation
- Build & register the MSIX package — see Build, Run & Deploy in
.github/agents/Agents.md. - Check for hard-coded secrets: search for
password,apikey,secret,connectionstringin.csfiles.
Verification Checklist
- No secrets are hard-coded
Must Read & Research
Agent Rule: Before any security-related change (auth, input handling, permissions, HTTP), you must fetch and review these references using
fetch_webpage. Apply what you learn.
| # | Reference | When to consult |
|---|---|---|
| 1 | .NET Security Best Practices | Any code handling credentials, tokens, or sensitive data |
| 2 | Secure coding guidelines for .NET | Input validation, exception handling, type safety |
| 3 | MSIX Security | Packaging, signing, or distribution changes |
| 4 | Package.appxmanifest capabilities | Adding or modifying app capabilities/permissions |