← Trabajos

Licensing/Auth System and API Development

Presupuesto: $500.0 FIXED / ⭐ 0.00 (0) USA

api-development, cloudflare, express-js, node.js, postgresql, typescript, nest.js, nginx, javascript, fastify

Cualificaciones preferidas

  • Experiencia: Experto
  • Inglés: Nativo
  • Job Success: 90%+
  • Se prefiere Rising Talent
We have a working production authentication, licensing, and secure software-delivery platform. We are looking for a senior backend/security engineer to audit the existing implementation, identify meaningful weaknesses, and implement targeted improvements without unnecessarily rewriting the system. This is not a greenfield project and it is not suitable for “vibe coding.” Do not apply if your normal workflow is to generate large patches you cannot independently explain, test, and defend. We need someone who can trace an unfamiliar codebase, reason about trust boundaries and state transitions, and support conclusions with source-level and runtime evidence. The private repository and detailed architecture will be shared with shortlisted applicants. Current technology - Node.js 20 and TypeScript - NestJS with Fastify - PostgreSQL with versioned migrations - Cloudflare, Workers, and private R2 storage - nginx and PM2 on a Linux VPS - Native Windows/C++ clients - libsodium-based cryptography: X25519, XChaCha20-Poly1305, Ed25519, and Argon2id - Discord webhooks and a Discord bot management integration What the system currently does - User registration and authentication using username, password, and hardware identity - One-HWID account binding, HWID resets, bans, and blacklisting - Time-limited and lifetime license keys with delayed activation and expiry enforcement - Encrypted, signed, replay-resistant client/server sessions - Session renewal, heartbeat-based authorization, revocation, and logout - Authenticated entitlement and configuration delivery - Secure release publication through Cloudflare Workers and R2 - Short-lived authenticated download URLs and one-time web download capabilities - Signed release metadata with client-side integrity verification before execution - Separate public and developer release channels - Scoped management API keys, IP restrictions, and mTLS-protected service/admin routes - Database-backed auth events, management audit records, file logging, and Discord alerts - Existing rate limiting and basic abuse/anomaly detection Initial scope We want to begin with a paid security and architecture audit. The successful developer may then continue into the remediation and deployment milestones. 1. Security and architecture review - Trace the complete handshake, login, registration, session, heartbeat, entitlement, launch-ticket, and download flows - Review trust boundaries between Cloudflare, nginx, the origin, PostgreSQL, Workers, R2, Discord services, and native clients - Identify exploitable findings, operational weaknesses, race conditions, and inconsistent authorization decisions 2. Rate limiting and abuse prevention An existing hybrid rate limiter is already present. We want it reviewed and strengthened where necessary. - Brute-force resistance across IP, account, HWID, and session dimensions - Persistent enforcement across application restarts - Safe handling of distributed or multi-process deployments - Prevention of account-lockout abuse and memory-exhaustion attacks - Correct rate limiting before expensive password-hashing or cryptographic work - Session-sharing, replay, automation, and suspicious download detection - Review of Cloudflare client-IP attribution and spoofed forwarding headers 3. Licensing and entitlement consistency - Ensure login, heartbeat, renewal, entitlement, launch-ticket, and download routes all use the same authoritative license rules - Test expiry boundaries, lifetime licenses, delayed activation, extension, revocation, and concurrent requests - Review transactional behavior and eliminate TOCTOU or race-condition gaps - Help formalize tier-based entitlements if multiple product tiers are introduced - Ensure release-channel access cannot be changed through client-controlled parameters 4. Logging, auditability, and monitoring Logging and database audit records already exist. We want to improve their operational usefulness. - Structured, searchable server logs - Request/session correlation without logging credentials, session keys, download URLs, or other bearer secrets - Reliable audit records for authentication, downloads, releases, and management actions - Retention and pruning policies - Alerting for abuse patterns and operational failures - Bounded retry/queue behavior for important Discord notifications - Clear separation between security events and expected session-expiry noise 5. API and error handling - Verify consistent error behavior across pre-authentication and authenticated routes - Preserve generic login failures to prevent user enumeration - Keep detailed diagnostics server-side while returning stable client-facing codes - Review DTO validation, payload limits, malformed envelope handling, and fail-closed behavior - Avoid breaking the existing wire protocol unless a change is justified and approved 6. PostgreSQL and performance - Profile real query paths rather than making speculative optimizations - Review indexes, query plans, connection-pool settings, and transaction boundaries - Reduce unnecessary database round trips - Review concurrency and locking around license activation, ticket consumption, release activation, and nonce consumption - Add safe cleanup strategies for expired sessions, tickets, nonces, leases, and audit data 7. Cloudflare and origin hardening The public API is already proxied through Cloudflare using HTTPS and Authenticated Origin Pulls. We want the deployment independently validated and hardened. - Confirm the origin cannot be reached directly from the public internet - Verify firewall restrictions and Cloudflare IP-range handling - Validate AOP/mTLS configuration and certificate lifecycle - Ensure Cloudflare headers are trusted only after the connection has been authenticated - Review Worker secrets, R2 permissions, cache behavior, and download capability validation - Verify internal bot/admin routes remain isolated from the public listener Expected deliverables - Evidence-backed audit report with severity and exploitability ratings - Prioritized remediation plan with estimated effort - Targeted source changes and PostgreSQL migrations - Automated security, regression, replay, concurrency, and expiry tests - Updated deployment and operational documentation - Staging and production deployment support - Post-deployment verification using fresh logs and runtime evidence - Clear documentation of any remaining assumptions or residual risk Required experience - Strong TypeScript and Node.js backend experience - Production experience with NestJS or Fastify - Strong PostgreSQL schema, indexing, transaction, and concurrency knowledge - Hands-on application-security and authentication-system experience - Cloudflare Workers, R2, reverse-proxy, TLS, and origin-lockdown experience - Familiarity with authenticated encryption, signatures, replay prevention, and secure session design - Linux, nginx, and PM2 production operations - Ability to review an existing protocol without casually replacing it with a fashionable framework Native Windows/C++ client experience is helpful but not mandatory.
Abrir en Upwork

AI proposal draft

Generate a short cover letter for this job. Edit before sending.

Sign in to generate an AI proposal draft.

Entrar