Skip to main content

Deployment safety

Current safety boundary​

The only controller route is unauthenticated and accepts uploaded images and CSV files. It writes temporary image files and may write debug overlays under ./data/debug. Exceptions return a generic 500 but are logged by the server.

This implementation is suitable only for a trusted deployment or an isolated local environment. Do not expose it directly to an untrusted public network and do not describe the current code as production-hardened.

Required hardening before public exposure​

The source does not yet establish:

  • Authentication or authorization.
  • Multipart upload-size and request-time limits.
  • File-type and CSV validation.
  • Structured client-safe error responses.
  • Controlled debug output, redaction, or retention.
  • Concurrency, resource, or OCR capacity guarantees.

Add and test those controls at the application or deployment boundary before serving untrusted users. A reverse proxy may reduce exposure, but its configuration is not part of this repository and should not be treated as an implemented Sunbeam feature.

Local deployment​

For local development, use:

./mvnw spring-boot:run

Then send the verified multipart request from Grade an exam. No container, cloud runtime, database, or public production recipe is established by the repository.