This project is an authorization server, so a vulnerability here is a vulnerability in everything that trusts its tokens. Reports are welcome and taken seriously.
Please do not open a public issue. Report privately through GitHub's private vulnerability reporting ("Report a vulnerability" on the Security tab).
Include what you can of:
- the component (authorization endpoint, token endpoint, DPoP verification,
ninja_dpop, key handling…) and the commit or version; - the steps or a proof of concept, ideally as a failing test;
- the impact as you see it, such as token forgery, replay, binding bypass or information disclosure;
- the RFC section you believe is violated, if one is.
- An acknowledgement within 3 working days.
- An assessment, and a fix plan or a reasoned "not a vulnerability", within 14 days.
- A fix on
mainwith a regression test, a CHANGELOG entry and a GitHub security advisory crediting you, unless you ask not to be named.
Please give a reasonable window, 90 days by default, before disclosing publicly, and do not test against deployments you do not own.
In scope: this repository's code, meaning the authserver, dpop,
ninja_dpop and demo_api packages, the Docker image and the CI
configuration.
Out of scope: the limitations the README lists as not protected against
(for example a stolen DPoP private key, or revocation latency at resource
servers that validate locally); the development defaults in
docker-compose.yml and .env.example, which are not secrets; and
vulnerabilities in dependencies, which should go to their maintainers,
though a heads-up here is appreciated.
Only the latest release on main receives security fixes.