Skip to content

security: complete v1 beta security review #72

Description

@RentnerKev

Summary

Perform the final comprehensive security review and remediation before RentnerProxy enters Beta.
This is a review and evidence gate, not a compliance certification.

The authoritative baseline is v1.0.0-alpha.6, plus the exact Beta features and fixes that will
ship.

Sequencing

Preparatory review may run earlier, but this issue must remain open until the final implementations
or explicit deferrals of CrowdSec #64, Forward Auth #65, and the NPM importer #66 are known.

Do not mark #72 complete before the final shipped forms of those features, upgrade/compatibility
#67/#68, and backup/restore #71 have been reviewed. Release-blocking findings must be remediated
and retested before #75 closes.

Review areas

Authentication and authorization

  • setup, login, password reset, invitations, TOTP, recovery codes, passkeys, sessions, disabled
    users, and rate limiting
  • RBAC, permission synchronization/enforcement, custom roles, last-owner protection, and
    transaction-time authorization
  • server-side enforcement for every new Beta operation

Proxy runtime and trust boundary

  • Caddy Admin API isolation and controller authentication
  • typed snapshot validation, revision/application boundary, rollback, and failed-apply behavior
  • unknown hosts, force HTTPS, WebSockets, HTTP/1.1, HTTP/2, and HTTP/3
  • trusted proxy/client-IP and original-scheme behavior, including forged Forwarded,
    X-Forwarded-For, X-Real-IP, and X-Forwarded-Proto
  • Alpha 6 live administration/reconciliation state

Access policies and Beta features

  • Basic Auth and IPv4/IPv6 rules
  • CrowdSec decision, credential, cache/staleness, failure, and custom-Caddy-module behavior if
    shipped
  • Forward Auth URL/header/credential/redirect/SSRF/failure behavior if shipped
  • NPM importer parsing, uploads, certificates/private keys, conflict handling, transactions, and
    result state if shipped

Certificates and secrets

  • private key and certificate upload/import
  • certificate candidates, durable operations/events, retry state, binding jobs, and restart
    recovery
  • ACME accounts, HTTP-01, DNS provider credentials, trusted CAs, and upstream TLS verification
  • application encryption key handling and contextual authenticated encryption

Web/API and files

  • CSRF, XSS, injection, redirects, SSRF, security headers, secret exposure, and error sanitization
  • path traversal, archive extraction, file permissions, restore validation, interruption, and
    backup disclosure
  • access/audit log privacy, pagination, retention, and redaction

GitHub and supply chain

  • workflow permissions, Actions pinning, PR-preview trust boundary, release automation, dependency
    review, CodeQL, Gitleaks, container scanning, SBOM/provenance, and residual signing/reproducibility
    limitations
  • Caddy/custom module source, version pinning, license, maintainer activity, advisories,
    transitive dependencies, and upgrade path

Finding handling

  • classify findings by severity and release impact
  • use the private SECURITY.md process for exploitable details or sensitive evidence
  • keep public issue/PR text sanitized
  • add regression tests for remediations
  • do not create a repository security-report document unless project policy is deliberately changed

Acceptance criteria

  • Final review covers Alpha 6 and every shipped Beta feature.
  • Findings are severity-classified and release-blocking findings are fixed and retested.
  • No known P0/P1 security blocker remains.
  • Required CI, CodeQL, Gitleaks, dependency, container, and production-smoke checks are green on
    the final reviewed heads.
  • Trusted client-IP, credentials, failure behavior, backup/restore, and supply-chain decisions
    have explicit evidence.
  • Residual risks and unsupported guarantees are documented without overstating certification.

Priority

P0 / final security gate for #75.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, accounts, sessions, passkeys, and access control.area: runtimeCaddy and privileged controller runtime behavior.securityPublic security hardening or remediation; disclose vulnerabilities privately.

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions