projects.back_all
CMSFull-StackSecurityFeatured

HelixCMS - Security-First Content Management System

Self-hosted CMS with Next.js 14, FastAPI, PostgreSQL, Redis. JWT RS256 auth, RBAC, MFA, plugin system, MinIO storage, MeiliSearch, comprehensive monitoring with Prometheus/Grafana.

Next.js 14 + TypeScript
Frontend
FastAPI + Python 3.12
Backend
PostgreSQL 16 + Redis 7
Database
JWT RS256 + RBAC + MFA
Security
projects.dataset

Self-hosted CMS with plugin system and enterprise-grade security

projects.approach

Security-first architecture with JWT RS256 auth, RBAC, MFA, plugin system, comprehensive monitoring, and production-ready deployment

projects.tech_stack
Next.js 14FastAPIPostgreSQL 16Redis 7MinIOMeiliSearchCeleryPrometheusGrafanaDockerTypeScriptPython 3.12
projects.keywords
Next.jsFastAPIPostgreSQLRedisJWTRBACMFADockerTypeScriptPython
projects.deep_dive

A security-first, self-hosted Content Management System built with modern technologies.

Technology Stack

  • Frontend: Next.js 14 (App Router), TypeScript, Tailwind CSS
  • Backend: FastAPI, Python 3.12, Pydantic v2
  • Database: PostgreSQL 16 (primary), Redis 7 (cache/sessions)
  • Storage: MinIO (S3-compatible object storage)
  • Search: MeiliSearch
  • Task Queue: Celery + Redis
  • Monitoring: Prometheus, Grafana, Loki, Promtail

Security Features

  • JWT RS256: Access tokens (15 min), refresh tokens (7 days, opaque, SHA-256 stored)
  • Refresh token rotation: Each use issues a new pair; reuse detection revokes the entire family
  • RBAC: Role-based permission checks at Nginx (UX) and FastAPI dependency (authoritative)
  • MFA: TOTP via pyotp, backup codes (SHA-256 hashed), mfa_pending JWT cookie
  • Audit log: Append-only audit_log table, every write operation logged
  • Rate limiting: Nginx zones — 5 req/min auth, 120 req/min API, 60 req/min global
  • CSP: Strict policy, no unsafe-eval, no unsafe-inline in script-src
  • Input validation: Pydantic v2 strict mode on all endpoints; MIME via magic bytes not Content-Type
  • Database isolation: helix_app has DML only (no DDL); helix_migrate for schema changes

Plugin System

  • ZIP-based plugins with manifest.json (slug, name, version, hooks) and main.py
  • JSON-RPC communication over subprocess stdin/stdout
  • Hooks for content.publish, media.upload, etc.
  • Sandboxed execution (minimal environment, 5s timeout per hook call)

Architecture

Browser
  └── Nginx (port 80/443)
        ├── /api/auth/       → Next.js (auth route handlers)
        ├── /api/v1/auth/login  → Backend (auth rate limit)
        ├── /api/v1/         → Backend (FastAPI)
        ├── /grafana/        → Grafana (monitoring)
        ├── /uploads/        → MinIO (public media)
        └── /                → Next.js (frontend)

Key Capabilities

  • Content management with rich text editor (TipTap)
  • Media library with optimization plugins
  • Taxonomy and content types
  • User management with roles and permissions
  • Webhooks for integrations
  • Backup and secret rotation scripts
  • Production-ready with TLS support