| Version | Supported |
|---|---|
| 1.0.x | ✅ Supported |
| < 1.0.0 | ❌ End of Life |
-
Password Hashing (PBKDF2):
- Hash Algorithm:
SHA-512 - Iteration Count:
100,000 - Key Length:
64 bytes (512 bits) - Salt Length:
16 bytes (128 bits)cryptographically secure random bytes generated viacrypto.randomBytes(16). - Verification:
crypto.timingSafeEqualprevents side-channel timing analysis attacks.
- Hash Algorithm:
-
Session Security:
- Session Tokens: 32 bytes of cryptographically random entropy (64-character hex strings).
- Validation: Explicit expiration timestamp checked on every request (
expires_at > NOW()). - Revocation: Instant database deletion on logout or administrative revocation via
/vcon.
-
Cloudflare Token Vault:
- Stored with database-level isolation.
- Client-side token masking prevents shoulder surfing and screen capture exposure.
- Real-time validity checks use direct official Cloudflare REST API endpoints (
/client/v4/user/tokens/verify).
-
Immutable Audit Trail:
- Every administrative operation (emergency abort, settings update, user creation, session revocation) produces an append-only entry in
app_audit_logs.
- Every administrative operation (emergency abort, settings update, user creation, session revocation) produces an append-only entry in
-
Cloudflare OAuth 2.0 Security & State Integrity:
- State Parameter: Cryptographically signed using HMAC-SHA256 with the OAuth Client Secret.
- Nonce & Expiration: Strict 15-minute validity window with random 8-byte nonces to prevent replay, state tampering, and CSRF attacks.
- Cross-Window Communication:
window.postMessagedispatch and listeners enforce strictwindow.location.originverification, blocking unauthorized cross-origin frames. - Reverse Proxy Protection: Explicit
trust proxyconfiguration with sanitized multi-hop header parsing.
If you discover a security vulnerability within this project, please send a detailed report to the security team or open a private security advisory on GitHub.
Please include:
- Description of the vulnerability.
- Proof of Concept (PoC) or reproducible steps.
- Potential impact and mitigation recommendations.