# ADR-007: Security Model ## Status Accepted ## Context The platform handles sensitive documentation and must resist supply-chain attacks, unauthorized access, data tampering, and common web vulnerabilities. The user explicitly requested a "paranoid" approach. ## Decision Implement defense in depth with the following layers: ### 1. Supply Chain Security - **Minimal dependencies**: Only well-established, security-audited libraries - **Pinned versions**: All Go modules pinned with go.sum checksums - **Vendoring option**: `go mod vendor` for air-gapped builds - **No build scripts**: Makefile only — no npm install, no curl | bash - **Reproducible builds**: Same source → same binary hash (via `-trimpath`) ### 2. Authentication Security - **Passkeys primary**: Phishing-resistant WebAuthn/FIDO2 - **Argon2id fallback**: Password Hashing Competition winner - **Constant-time comparison**: All secret verification uses `subtle.ConstantTimeCompare` - **Rate limiting**: Auth endpoints: 5 attempts per minute per IP - **Session hardening**: Signed, HttpOnly, Secure, SameSite=Strict cookies ### 3. Authorization Security - **RBAC**: Read/write/admin per document and collection - **Principle of least privilege**: Default to no access, explicitly grant - **Content verification**: SHA-256 hash verified on every read - **Audit logging**: Every access logged with actor, resource, timestamp, IP ### 4. Input Validation - **Markdown sanitization**: Goldmark renders to safe HTML; no raw HTML injection - **File upload validation**: Magic number check, extension whitelist, size limits - **Path canonicalization**: All file paths resolved to absolute, checked against allowlist - **Query parameterization**: All SQL uses parameterized queries (no string concatenation) ### 5. Transport Security - **TLS 1.3**: Minimum version enforced - **HSTS**: Strict-Transport-Security header with preload - **CSP**: Content-Security-Policy restricts script sources to nonce-tagged inline and same-origin - **CORS**: Restrictive — only same-origin by default ### 6. Operational Security - **No secrets in logs**: All tokens, passwords redacted - **No secrets in environment**: Configuration from file or encrypted env vars - **Read-only container**: Filesystem mounted read-only except `/data` - **Non-root user**: Container runs as unprivileged user - **Health checks**: `/health` endpoint verifies all dependencies ## Consequences ### Positive - Resistant to OWASP Top 10 vulnerabilities - Supply-chain attacks mitigated by minimal dependencies - Audit trail provides accountability - Container hardening reduces attack surface ### Negative - CSP can block legitimate resources (requires careful tuning) - Rate limiting may affect legitimate users behind NAT (mitigated by user-aware limits) - Security reviews required for any new dependency - More complex local development (TLS certs, CSP headers) ## References - OWASP Top 10: https://owasp.org/www-project-top-ten/ - Go Security Best Practices: https://go.dev/security - WebAuthn Security: https://www.w3.org/TR/webauthn-2/#security-considerations - Content Security Policy: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP