Skip to content

Security: Sarabanda97/TuneBridge

Security

SECURITY.md

Security

Implemented or scaffolded safeguards:

  • HTTPS-only supported provider host allowlist.
  • Rejection of playlist URLs containing credentials.
  • No arbitrary server-side URL fetching.
  • Zod validation for external input.
  • PKCE helper generation.
  • OAuth redirect path validation.
  • Secure, same-site consent cookie configuration.
  • Token encryption interface.
  • AES-GCM token encryptor for Spotify refresh-token storage.
  • Spotify OAuth state hashing, short expiration, and single-use consumption.
  • Spotify token refresh and disconnect storage flow.
  • Rate limiting abstraction.
  • Secure response headers and CSP in next.config.ts.
  • Correlation IDs on JSON responses.
  • Secret redaction helper.
  • Provider tokens separated in database schema.

Production work still required:

  • Persist OAuth state hashes and enforce one-time consumption.
  • Move OAuth state and token storage from in-memory foundation stores to Supabase.
  • Add Supabase RLS policies for signed anonymous sessions.
  • Store rate-limit counters in Supabase.
  • Complete provider-specific OAuth callback validation.

There aren't any published security advisories