Summary
Perform the final comprehensive security review and remediation before RentnerProxy enters Beta.
This is a review and evidence gate, not a compliance certification.
The authoritative baseline is v1.0.0-alpha.6, plus the exact Beta features and fixes that will
ship.
Sequencing
Preparatory review may run earlier, but this issue must remain open until the final implementations
or explicit deferrals of CrowdSec #64, Forward Auth #65, and the NPM importer #66 are known.
Do not mark #72 complete before the final shipped forms of those features, upgrade/compatibility
#67/#68, and backup/restore #71 have been reviewed. Release-blocking findings must be remediated
and retested before #75 closes.
Review areas
Authentication and authorization
- setup, login, password reset, invitations, TOTP, recovery codes, passkeys, sessions, disabled
users, and rate limiting
- RBAC, permission synchronization/enforcement, custom roles, last-owner protection, and
transaction-time authorization
- server-side enforcement for every new Beta operation
Proxy runtime and trust boundary
- Caddy Admin API isolation and controller authentication
- typed snapshot validation, revision/application boundary, rollback, and failed-apply behavior
- unknown hosts, force HTTPS, WebSockets, HTTP/1.1, HTTP/2, and HTTP/3
- trusted proxy/client-IP and original-scheme behavior, including forged
Forwarded,
X-Forwarded-For, X-Real-IP, and X-Forwarded-Proto
- Alpha 6 live administration/reconciliation state
Access policies and Beta features
- Basic Auth and IPv4/IPv6 rules
- CrowdSec decision, credential, cache/staleness, failure, and custom-Caddy-module behavior if
shipped
- Forward Auth URL/header/credential/redirect/SSRF/failure behavior if shipped
- NPM importer parsing, uploads, certificates/private keys, conflict handling, transactions, and
result state if shipped
Certificates and secrets
- private key and certificate upload/import
- certificate candidates, durable operations/events, retry state, binding jobs, and restart
recovery
- ACME accounts, HTTP-01, DNS provider credentials, trusted CAs, and upstream TLS verification
- application encryption key handling and contextual authenticated encryption
Web/API and files
- CSRF, XSS, injection, redirects, SSRF, security headers, secret exposure, and error sanitization
- path traversal, archive extraction, file permissions, restore validation, interruption, and
backup disclosure
- access/audit log privacy, pagination, retention, and redaction
GitHub and supply chain
- workflow permissions, Actions pinning, PR-preview trust boundary, release automation, dependency
review, CodeQL, Gitleaks, container scanning, SBOM/provenance, and residual signing/reproducibility
limitations
- Caddy/custom module source, version pinning, license, maintainer activity, advisories,
transitive dependencies, and upgrade path
Finding handling
- classify findings by severity and release impact
- use the private SECURITY.md process for exploitable details or sensitive evidence
- keep public issue/PR text sanitized
- add regression tests for remediations
- do not create a repository security-report document unless project policy is deliberately changed
Acceptance criteria
Priority
P0 / final security gate for #75.
Summary
Perform the final comprehensive security review and remediation before RentnerProxy enters Beta.
This is a review and evidence gate, not a compliance certification.
The authoritative baseline is
v1.0.0-alpha.6, plus the exact Beta features and fixes that willship.
Sequencing
Preparatory review may run earlier, but this issue must remain open until the final implementations
or explicit deferrals of CrowdSec #64, Forward Auth #65, and the NPM importer #66 are known.
Do not mark #72 complete before the final shipped forms of those features, upgrade/compatibility
#67/#68, and backup/restore #71 have been reviewed. Release-blocking findings must be remediated
and retested before #75 closes.
Review areas
Authentication and authorization
users, and rate limiting
transaction-time authorization
Proxy runtime and trust boundary
Forwarded,X-Forwarded-For,X-Real-IP, andX-Forwarded-ProtoAccess policies and Beta features
shipped
result state if shipped
Certificates and secrets
recovery
Web/API and files
backup disclosure
GitHub and supply chain
review, CodeQL, Gitleaks, container scanning, SBOM/provenance, and residual signing/reproducibility
limitations
transitive dependencies, and upgrade path
Finding handling
Acceptance criteria
the final reviewed heads.
have explicit evidence.
Priority
P0 / final security gate for #75.