3.1 KiB
3.1 KiB
ADR-007: Security Model
Status
Accepted
Context
The platform handles sensitive documentation and must resist supply-chain attacks, unauthorized access, data tampering, and common web vulnerabilities. The user explicitly requested a "paranoid" approach.
Decision
Implement defense in depth with the following layers:
1. Supply Chain Security
- Minimal dependencies: Only well-established, security-audited libraries
- Pinned versions: All Go modules pinned with go.sum checksums
- Vendoring option:
go mod vendorfor air-gapped builds - Centralized automation:
mise run ...tasks only — no ad hoc shell scripts, no curl | bash - Reproducible builds: Same source → same binary hash (via
-trimpath)
2. Authentication Security
- Passkeys primary: Phishing-resistant WebAuthn/FIDO2
- Argon2id fallback: Password Hashing Competition winner
- Constant-time comparison: All secret verification uses
subtle.ConstantTimeCompare - Rate limiting: Auth endpoints: 5 attempts per minute per IP
- Session hardening: Signed, HttpOnly, Secure, SameSite=Strict cookies
3. Authorization Security
- RBAC: Read/write/admin per document and collection
- Principle of least privilege: Default to no access, explicitly grant
- Content verification: SHA-256 hash verified on every read
- Audit logging: Every access logged with actor, resource, timestamp, IP
4. Input Validation
- Markdown sanitization: Goldmark renders to safe HTML; no raw HTML injection
- File upload validation: Magic number check, extension whitelist, size limits
- Path canonicalization: All file paths resolved to absolute, checked against allowlist
- Query parameterization: All SQL uses parameterized queries (no string concatenation)
5. Transport Security
- TLS 1.3: Minimum version enforced
- HSTS: Strict-Transport-Security header with preload
- CSP: Content-Security-Policy restricts script sources to nonce-tagged inline and same-origin
- CORS: Restrictive — only same-origin by default
6. Operational Security
- No secrets in logs: All tokens, passwords redacted
- No secrets in environment: Configuration from file or encrypted env vars
- Read-only container: Filesystem mounted read-only except
/data - Non-root user: Container runs as unprivileged user
- Health checks:
/healthendpoint verifies all dependencies
Consequences
Positive
- Resistant to OWASP Top 10 vulnerabilities
- Supply-chain attacks mitigated by minimal dependencies
- Audit trail provides accountability
- Container hardening reduces attack surface
Negative
- CSP can block legitimate resources (requires careful tuning)
- Rate limiting may affect legitimate users behind NAT (mitigated by user-aware limits)
- Security reviews required for any new dependency
- More complex local development (TLS certs, CSP headers)
References
- OWASP Top 10: https://owasp.org/www-project-top-ten/
- Go Security Best Practices: https://go.dev/security
- WebAuthn Security: https://www.w3.org/TR/webauthn-2/#security-considerations
- Content Security Policy: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP