| Version | Supported |
|---|---|
| 0.1.x | ✅ |
If you discover a security vulnerability in SaviTools, please report it responsibly:
- Do not open a public GitHub issue for security vulnerabilities.
- Email security concerns to: security@savitura.com
- Include a detailed description of the vulnerability.
- If possible, provide steps to reproduce or a proof-of-concept.
We aim to acknowledge reports within 48 hours and will work with you to understand and address the issue promptly.
SaviTools implements the following security measures:
- CORS: Restricted origins via
WEB_ORIGINenvironment variable - Rate Limiting: Configurable via
THROTTLE_LIMITandTHROTTLE_TTL - Input Validation: All API inputs are validated using class-validator
- HMAC-SHA256 Signing: Outbound webhooks (Webhook Tester, contract-event replay, monitor alerts) are signed with a per-request secret or
WEBHOOK_SIGNING_SECRET - Timestamp Verification: The signature covers
<timestamp>.<body>, so a captured request cannot be replayed verbatim. Reject timestamps older than the replay window (default 300s) or more than 60s in the future - Signature Header:
X-SaviTools-Signaturewith formatsha256=<hex>, paired withX-SaviTools-Timestamp(integer Unix seconds)
- JWT Tokens: Secure session management with refresh token rotation
- Password Hashing: Argon2 for password storage
- SSRF Protection: Guards on outbound requests from Playground and Webhook modules
- TLS: All external API calls use HTTPS
The following security headers are set on all responses:
| Header | Value | Purpose |
|---|---|---|
Content-Security-Policy |
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self' data:; connect-src 'self' https://horizon-testnet.stellar.org https://horizon.stellar.org https://friendbot.stellar.org https://api.fluxa.io https://api.crowdpay.io wss://*.stellar.org; frame-ancestors 'self'; form-action 'self'; base-uri 'self'; object-src 'none' |
Mitigates XSS, injection, and unauthorized framing |
X-Content-Type-Options |
nosniff |
Prevents MIME-type sniffing |
Referrer-Policy |
strict-origin-when-cross-origin |
Controls referrer information sent with requests |
Permissions-Policy |
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=(), interest-cohort=() |
Restricts browser features and APIs |
Strict-Transport-Security |
max-age=63072000; includeSubDomains; preload (production only) |
Enforces HTTPS |
X-DNS-Prefetch-Control |
on |
Enables DNS prefetching for performance |
X-Powered-By |
Removed | Hides Next.js version information |
| Variable | Description |
|---|---|
WEB_ORIGIN |
Allowed CORS origin |
THROTTLE_TTL |
Rate limit window (ms) |
THROTTLE_LIMIT |
Max requests per window |
WEBHOOK_SIGNING_SECRET |
HMAC key for webhook signatures |
JWT_SECRET |
Secret for JWT token signing |
We appreciate the security research community and will acknowledge researchers who report valid vulnerabilities (with permission) in our release notes.