| Version | Supported |
|---|---|
| 0.1.x | ✅ |
If you discover a security vulnerability, please report it responsibly.
Do NOT open a public GitHub Issue for security vulnerabilities.
Instead, email the maintainers with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
You should receive a response within 48 hours. We will work with you to understand the issue and coordinate a fix before any public disclosure.
- Password hashing: PBKDF2 with SHA-256, 100,000 iterations, 16-byte random salt, 32-byte hash. Stored as
hex(salt).hex(hash). - JWT tokens: HS256 algorithm via the jose library, 24-hour expiry. Payload contains user ID, codename, role, and clearance level.
- JWT_SECRET: Not defined in
wrangler.toml— a plaintext[vars]entry would be redeployed (and would clobber a same-named secret) on everywrangler deploy. Local dev reads it fromworker/.dev.vars(gitignored, copy from.dev.vars.example). Production must set it viawrangler secret put JWT_SECRET, run once against the deployed Worker — never commit the real value anywhere.
- CORS origins are configured via the
CORS_ORIGINSenvironment variable inwrangler.toml. - Supports exact match and wildcard subdomain patterns (e.g.,
https://*.scp.lat). - Credentials are enabled for authenticated cross-origin requests.
- Allowed methods: GET, POST, PUT, DELETE, OPTIONS.
All user input is validated server-side before database operations:
- Codenames: 3-32 characters, alphanumeric and underscore only (
/^[a-zA-Z0-9_]+$/) - Passwords: 8-128 characters
- Profile updates: Current password required when changing password
- Uses Cloudflare D1 (SQLite-based) with parameterized queries.
- 12 tables:
users,scp_entries,crawl_state,browsing_history,bookmarks,proposals,proposal_votes,entry_reports,system_logs,ai_conversations,tag_categories,tags,entry_tags. - Unique constraint on
users.codename. - Index on codename for efficient lookups.
Before deploying to production:
- Set a strong, unique
JWT_SECRETviawrangler secret put JWT_SECRET(cdworker/) — do not put it inwrangler.toml - Set
GLM_API_KEYfor AI chat functionality - Verify
CORS_ORIGINSonly includes your actual domains - Ensure D1 database bindings are correctly configured
- Verify Durable Object bindings are configured
- Review and test all authentication flows
- Enable Cloudflare's built-in DDoS protection