Files
web/docs/THREAT_MODEL.md
T
gamertan a18f1dd22a
verify / verify (push) Successful in 3m1s
security: harden first preview boundaries
Sanitized snapshot of private source 13a965dd6ea705dd92499f7dbeaa00c25c15247d. Require same-origin evidence for unsafe methods, fail closed on invalid authentication middleware configuration, and bound untrusted request metadata.

AI-Assistance: OpenAI Codex assisted implementation, testing, and security review.
Signed-off-by: Cole Speelman <crspeelman@gmail.com>
2026-08-16 19:20:14 -04:00

1.6 KiB

Threat model

The toolkit treats the public network, forwarding headers, request targets, cookies, credentials, and stored request records as untrusted. Application code, the configured trusted-proxy set, server filesystem permissions, and explicitly selected storage adapters are trusted.

Controls include explicit proxy trust, bounded parsing, cryptographic request and session identifiers, digest-only session storage, Argon2id passwords, constant-time comparisons, same-origin and CSRF primitives, fail-closed storage errors, and separate safe/sensitive analytics projections.

Unsafe methods without an exact Origin or trustworthy same-origin Fetch Metadata fail the origin check. Authentication middleware fails closed when its service or __Host- cookie policy is invalid. Imported request records have bounded byte and duration fields before analytics sums them.

The toolkit does not sandbox application handlers, secure an incorrectly configured reverse proxy, authorize application routes automatically, encrypt a compromised host, or decide how long an operator may lawfully retain personal request evidence.

Local storage adapters assume the parent directory and host account are trusted. They reject a symlink at the configured final path and apply private file modes, but they do not defend against a concurrent privileged actor replacing path ancestors during an open. The synchronous JSONL adapter deliberately favors durable, bounded evidence over maximum request throughput; the application owns rotation, retention, disk monitoring, and health escalation.