Senior TypeScript/Node dev: security hardening + CI for UK health platform
Бюджет: $4750.0
FIXED /
⭐ 0.00 (0)
United Kingdom
typescript, express-js, postgresql, node.js, web-application-security, cicd
Предпочитана квалификация
- Опит: Експерт
I run an online pharmacy and prescribing service here in the UK, regulated by the GPhC, and I've had a platform built for it over the past year or so. It works - patients go through an eligibility check, a prescriber reviews and approves, payments run through Stripe and GoCardless. What it isn't is properly ready to go live. Rather than guess at what was left to do, I paid to have the codebase reviewed independently, task by task.
This job is the first chunk off that list: security hardening, getting the build clean, and setting up CI. Somewhere between 8 and 12 days of work, fixed price.
I'll be straight about why it's carved up this way. I don't know you, you don't know me, and there's a lot more work sitting behind this piece. I'd rather we did something small and well-defined first and saw how it went.
What you'd be working on
pnpm monorepo, TypeScript top to bottom. Express 5 with Drizzle and Postgres on the server, React 19 and Vite on the front. Stripe for cards, GoCardless for direct debits, both webhooks signature-verified.
There's already a fair bit in place: Helmet with a proper CSP, rate limiting on the auth routes, JWT sessions in httpOnly cookies with server-side revocation, TOTP MFA that's actually enforced, bcrypt, account lockout, an append-only audit log. I mention all that because "security hardening" in a job ad usually means the thing is a disaster. This one isn't. It's a decent build that needs finishing.
The tasks
1. Get the repo typechecking clean. There are 13 pre-existing errors - they've been counted, and they come down to a handful of causes.
2. Set up CI. Typecheck, lint, tests and a dependency audit on every PR, and block the merge if it's red. There's nothing there at the moment.
3. CSRF protection on the cookie-authenticated routes that change state. While you're in there, the non-production CORS config is far too permissive and there's no explicit body size limit.
4. Rate limiting needs extending to the rest of the endpoints that change state or can be enumerated. Keyed per-account as well as per-IP, and configured properly to sit behind a proxy - that last bit gets missed a lot.
5. Two dependency advisories to patch, and our vulnerability-management doc needs updating to match.
6. Two access-control fixes, plus one route that shouldn't be publicly reachable. Each with a test. One thing I'll say plainly here: this part is already scoped. All 81 endpoints were swept and we know exactly which ones are affected, so please don't price in time to go hunting for more. You'll get the detail once we're talking under NDA.
7. There's a form on the front end that tells people their message has been sent when it hasn't. That needs sorting.
8. A dev-only guard that keys off an environment variable in a way that fails open. Flip it so it fails closed, and put a check in CI so it stays that way.
Who I'm after
Someone senior who's done this on a real Express app in production. If you know why SameSite=Lax doesn't buy you CSRF protection, and you've written tests against the authorization paths rather than just the happy path, you're the sort of person I want. Health or finance background is a bonus but not essential.
UK or European hours would suit best. And because this is patient data, I'm going to ask where your team sits and whether anyone outside the UK/EEA would be able to see it. Not to catch anyone out - it's just something I have to be able to answer for.
How I work
Everything through the repo, short branches, PRs. Nothing turns up as a zip file at the end.
Fixes come with a test that fails without them.
When you tell me something's fixed I'll want to see it. For an access control that means showing me the request getting rejected, not the one that works. I'll send you a one-page note on what counts as evidence before you start, so we're not arguing about it later.
No real patient data in dev or test, synthetic only. There's a DPA to sign before you get repo access.
IP in the code, the infrastructure and the docs comes to the company on payment. Nothing copyleft without asking me first.
Named people only, MFA on everything, access switched off and secrets rotated when we're done.
If you spot something I don't know about - a data exposure, an access-control hole - tell me. I'd genuinely rather hear it.
Next steps
Please answer the screening questions. I'll read those before I read the cover letter. If you're shortlisted I'll send the full spec for this workstream under NDA - real file paths, acceptance criteria per task, and the day estimate I'm working to. I'd like to see your estimate next to mine before I award anything. If yours is a long way off in either direction that's worth a conversation, it doesn't rule you out.
Ready to start as soon as I find the right person.
Отвори в Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Вход