You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
51 lines
2.5 KiB
51 lines
2.5 KiB
|
5 months ago
|
# Security Policy
|
||
|
|
|
||
|
|
Active is not production-ready until `0.1.0` is tagged and the security checklist in `before_0_1.md` is closed.
|
||
|
|
|
||
|
|
## Reporting
|
||
|
|
|
||
|
|
Do not open public issues for suspected vulnerabilities.
|
||
|
|
|
||
|
|
Use GitHub Security Advisories for this repository when available. If advisories are not available in the current hosting setup, contact the maintainer through a private channel and include:
|
||
|
|
|
||
|
|
- affected module and commit hash;
|
||
|
|
- reproduction steps;
|
||
|
|
- expected impact;
|
||
|
|
- whether credentials, cookies, tokens, permissions or cross-tenant data are involved.
|
||
|
|
|
||
|
|
## Threat Model Summary
|
||
|
|
|
||
|
|
Security-sensitive modules are split by responsibility:
|
||
|
|
|
||
|
|
- `auth` proves identity, manages login flows, CSRF, OAuth state/PKCE binding and session binding.
|
||
|
|
- `sess` owns session continuity, revocation and browser/session synchronization.
|
||
|
|
- `perm` authorizes actions for an authenticated actor and tenant.
|
||
|
|
- `cach` must not leak data across actor, tenant, permission, locale or session scopes.
|
||
|
|
- `stor` must not persist secrets unless an explicit adapter and policy say so.
|
||
|
|
- `logr` must redact sensitive payloads and centralize security diagnostics.
|
||
|
|
|
||
|
|
## Current Guarantees
|
||
|
|
|
||
|
|
- Authentication is server-authoritative; the active client reflects state but does not protect routes by itself.
|
||
|
|
- Session cookies and auth helper cookies use explicit cookie constants.
|
||
|
|
- CSRF tokens are required for state-changing auth endpoints.
|
||
|
|
- OAuth flows store state and PKCE verifier server-side and verify the persisted verifier before callback completion.
|
||
|
|
- Permission client cache keys include scope when actor or explicit scope is present.
|
||
|
|
- Memory adapters are for tests, local development and SSR isolation; they warn when instantiated in production mode.
|
||
|
|
|
||
|
|
## Explicit Non-Guarantees Before 0.1
|
||
|
|
|
||
|
|
- MFA is not part of the stable public auth engine surface.
|
||
|
|
- Production WebAuthn/passkeys are not included.
|
||
|
|
- The OAuth provider catalog is not included.
|
||
|
|
- No module should be treated as audited for regulated production workloads.
|
||
|
|
|
||
|
|
## Security Rules For Changes
|
||
|
|
|
||
|
|
- Never add a public route, cookie name, header name, error code, event name or logger category as an inline string.
|
||
|
|
- Never cache private data without actor/tenant scope.
|
||
|
|
- Never persist access tokens, refresh tokens, OTPs, passwords or CSRF tokens in `stor`.
|
||
|
|
- Never use `localStorage` as the source of truth for authentication.
|
||
|
|
- Add regression tests for every security bug fix.
|
||
|
|
- If a module exports a method in the stable surface, it must work or be removed from the surface.
|