Security — Active

Security model

Active treats identity, sessions, permissions, storage and cache as separate security surfaces. The active client improves UX, but the server layer remains authoritative.

Active should not be tagged as 1.0 until the security release checklist is closed and documented in docs/SECURITY.md. MFA and production WebAuthn/passkeys are intentionally outside the stable surface unless the release notes explicitly include them.

Report privately

Do not open public issues for suspected vulnerabilities. Use the private advisory flow described in docs/SECURITY.md. Include the affected module, commit hash, reproduction steps and whether cookies, tokens, permissions or cross-tenant data are involved.

Module boundaries

Security-sensitive work starts by choosing the correct owner. Avoid moving authority to the client just because it is convenient for a page.

Surface Rule Failure mode
auth Flows are server-side and short-lived. Login CSRF, stale flow replay, OAuth state confusion.
$session The session cookie is the continuity source. Session fixation or logout that resurrects state.
perm Authorization decisions are actor and tenant scoped. Actor A decisions leak into actor B after hydrate.
$cache Private cache entries require explicit scope. Cross-user, cross-tenant or stale-permission data leaks.
$storage Client storage is not a secret vault. Tokens readable by script or browser extensions.

Cookies and CSRF

The session cookie belongs to $session. auth owns helper cookies and CSRF validation for auth actions. Defaults are intentionally strict for the browser case.

OAuth and PKCE

OAuth state and the PKCE verifier are created by startOAuth and persisted in the server flow. completeOAuth reads the stored verifier, verifies that it still matches the flow hash and passes it to the provider adapter. The callback does not trust a browser-supplied verifier.

Storage rule

Use $storage for drafts and non-secret local state. Use $prefs for user preference intent. Do not persist access tokens, refresh tokens, passwords, OTPs or CSRF tokens in client storage.

Regression requirements

  • Every security bug fix needs a regression test.
  • Every exported stable method must work or be removed from the stable surface.
  • Every memory adapter must warn in production mode.
  • Every private cache or permission decision must include an actor, tenant or explicit scope.
  • Every public route, cookie, header, event and logger message must come from constants.