drupal/security_recipe
最新稳定版本:1.0.1
Composer 安装命令:
composer require drupal/security_recipe
包简介
Security recipe with security.txt and essential security modules.
README 文档
README
This package provides essential security modules and configurations for Drupal sites.
Installation
Apply the recipe:
drush recipe recipes/contrib/security_packageRun post-installation commands:
drush cache:rebuild drush security-review:run
Components
Installed Security Modules
- Flood Control: Limits login and form submission attempts
- Two-Factor Authentication (2FA): Provides multi-factor authentication
- Security Kit: Implements various security hardening features
- Security Review: Automated security review tool
Security.txt Setup
A security.txt file should be placed in web/.well-known/security.txt. You can generate one using the official generator at https://securitytxt.org/
Example security.txt content:
# Security.txt file
# For more information: https://securitytxt.org/
Contact: mailto:security@example.com
Expires: 2025-12-31T23:59:59+00:00
Preferred-Languages: en, nl
Policy: https://example.com/security-policy
Hiring: https://example.com/jobs/security
Recommended Next Steps
- Review and customize the security.txt file using the generator at https://securitytxt.org/
- Configure 2FA for user roles
- Run a security review with:
drush security-review:run - Review Security Kit settings
Configuration Details
Flood Control Settings
- Contact form rate limit: 3 attempts
- Contact form user limit: 5 attempts
- User login rate limit: 5 attempts
- User login user limit: 5 attempts
TFA Settings
- Required for administrator and editor roles
- Uses TOTP (Time-based One-Time Password) validation
- 2-minute time skew allowed
- Site name prefix enabled
Security Kit Settings
- Content Security Policy (CSP) enabled
- XSS protection enabled
- CSRF protection enabled
- Clickjacking protection enabled
统计信息
- 总下载量: 6
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 0
- 点击次数: 0
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: GPL-2.0
- 更新时间: 2025-05-19