You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

51 lines
2.5 KiB

# Security Policy
Active is not production-ready until `0.1.0` is tagged and the security checklist in `before_0_1.md` is closed.
## Reporting
Do not open public issues for suspected vulnerabilities.
Use GitHub Security Advisories for this repository when available. If advisories are not available in the current hosting setup, contact the maintainer through a private channel and include:
- affected module and commit hash;
- reproduction steps;
- expected impact;
- whether credentials, cookies, tokens, permissions or cross-tenant data are involved.
## Threat Model Summary
Security-sensitive modules are split by responsibility:
- `auth` proves identity, manages login flows, CSRF, OAuth state/PKCE binding and session binding.
- `sess` owns session continuity, revocation and browser/session synchronization.
- `perm` authorizes actions for an authenticated actor and tenant.
- `cach` must not leak data across actor, tenant, permission, locale or session scopes.
- `stor` must not persist secrets unless an explicit adapter and policy say so.
- `logr` must redact sensitive payloads and centralize security diagnostics.
## Current Guarantees
- Authentication is server-authoritative; the active client reflects state but does not protect routes by itself.
- Session cookies and auth helper cookies use explicit cookie constants.
- CSRF tokens are required for state-changing auth endpoints.
- OAuth flows store state and PKCE verifier server-side and verify the persisted verifier before callback completion.
- Permission client cache keys include scope when actor or explicit scope is present.
- Memory adapters are for tests, local development and SSR isolation; they warn when instantiated in production mode.
## Explicit Non-Guarantees Before 0.1
- MFA is not part of the stable public auth engine surface.
- Production WebAuthn/passkeys are not included.
- The OAuth provider catalog is not included.
- No module should be treated as audited for regulated production workloads.
## Security Rules For Changes
- Never add a public route, cookie name, header name, error code, event name or logger category as an inline string.
- Never cache private data without actor/tenant scope.
- Never persist access tokens, refresh tokens, OTPs, passwords or CSRF tokens in `stor`.
- Never use `localStorage` as the source of truth for authentication.
- Add regression tests for every security bug fix.
- If a module exports a method in the stable surface, it must work or be removed from the surface.

Powered by TurnKey Linux.