You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

2.5 KiB

Security Policy

Active is not production-ready until 0.1.0 is tagged and the security checklist in before_0_1.md is closed.

Reporting

Do not open public issues for suspected vulnerabilities.

Use GitHub Security Advisories for this repository when available. If advisories are not available in the current hosting setup, contact the maintainer through a private channel and include:

  • affected module and commit hash;
  • reproduction steps;
  • expected impact;
  • whether credentials, cookies, tokens, permissions or cross-tenant data are involved.

Threat Model Summary

Security-sensitive modules are split by responsibility:

  • auth proves identity, manages login flows, CSRF, OAuth state/PKCE binding and session binding.
  • sess owns session continuity, revocation and browser/session synchronization.
  • perm authorizes actions for an authenticated actor and tenant.
  • cach must not leak data across actor, tenant, permission, locale or session scopes.
  • stor must not persist secrets unless an explicit adapter and policy say so.
  • logr must redact sensitive payloads and centralize security diagnostics.

Current Guarantees

  • Authentication is server-authoritative; the active client reflects state but does not protect routes by itself.
  • Session cookies and auth helper cookies use explicit cookie constants.
  • CSRF tokens are required for state-changing auth endpoints.
  • OAuth flows store state and PKCE verifier server-side and verify the persisted verifier before callback completion.
  • Permission client cache keys include scope when actor or explicit scope is present.
  • Memory adapters are for tests, local development and SSR isolation; they warn when instantiated in production mode.

Explicit Non-Guarantees Before 0.1

  • MFA is not part of the stable public auth engine surface.
  • Production WebAuthn/passkeys are not included.
  • The OAuth provider catalog is not included.
  • No module should be treated as audited for regulated production workloads.

Security Rules For Changes

  • Never add a public route, cookie name, header name, error code, event name or logger category as an inline string.
  • Never cache private data without actor/tenant scope.
  • Never persist access tokens, refresh tokens, OTPs, passwords or CSRF tokens in stor.
  • Never use localStorage as the source of truth for authentication.
  • Add regression tests for every security bug fix.
  • If a module exports a method in the stable surface, it must work or be removed from the surface.

Powered by TurnKey Linux.