Do not open public issues for suspected vulnerabilities.
Use GitHub Security Advisories for this repository when available. If advisories are not available in the current hosting setup, contact the maintainer through a private channel and include:
- affected module and commit hash;
- reproduction steps;
- expected impact;
- whether credentials, cookies, tokens, permissions or cross-tenant data are involved.
## Threat Model Summary
Security-sensitive modules are split by responsibility:
-`sess` owns the primary session cookie; `auth` only owns helper cookies for CSRF, flows, device hints or refresh mode when explicitly enabled.
- Secret cookies must be `HttpOnly`, `Secure`, path-scoped to `/`, and must not set `Domain` unless a deployment has reviewed subdomain trust.
- Same-site browser flows default to strict/lax same-site cookies. Cross-site deployments must opt in deliberately and keep CSRF checks enabled.
- JavaScript-readable cookies are only for non-secret hints. Access tokens, refresh tokens, OTPs, passwords and CSRF signing secrets must not be readable by client code.
### CSRF flow
- State-changing browser auth routes must require a CSRF token and validate origin/fetch metadata when the hosting framework exposes those headers.
- CSRF tokens are issued by `auth`, sent by `arts/auth`, verified server-side, and scoped to the configured flow/window.
- Missing, expired, replayed or mismatched CSRF tokens must fail before credential, session or provider state is mutated.
### Refresh rotation
- Refresh mode, when enabled, must use opaque tokens stored server-side as hashes.
- Rotation is single-use: consuming a refresh token creates a child token, marks the parent consumed and binds the new token to the same family/session.
- Reuse outside the configured grace window is treated as replay and must revoke the whole refresh family and the linked session binding.
- Database adapters must perform refresh lookup/consume/child creation under a row lock or equivalent transaction boundary.
### OAuth state and PKCE binding
- OAuth/OIDC flows must persist `state`, `nonce` and PKCE verifier material server-side in an expiring flow record.
- Callback completion must compare the returned state with the stored state and send the stored verifier to the provider token exchange.
- Email-based account linking must not happen automatically unless the provider marks the email as verified and the application explicitly opts into that policy.
- Provider tokens are not persisted by default; applications that keep them need a separate vault/adapter review.
### MFA status
- MFA is not part of the stable `0.1` auth surface. Any future MFA/passkey/WebAuthn work must remain experimental until it has flow storage, replay protection, recovery behavior and regression tests.
-`auth` may expose AAL/AMR metadata from authenticated sessions, but `perm` decides whether that assurance is sufficient for an action.
### Actor and tenant model
-`actorId` is never globally meaningful without `tenantId`.
- Auth credential uniqueness, linked OAuth accounts, session bindings and devices must all be tenant-scoped.
- Permission decisions and cache keys must include actor/scope information when an authenticated actor is present.
- Login/logout, tenant switch, permission change and session revoke must invalidate actor/permission-scoped caches.