issuetracker / Architecture / Security Architecture

Security Architecture

Authentication establishes the identity of the caller.

1 min readApplies to v0.6.0
On this page ▾
  1. Authentication
  2. Authorization
  3. Sensitive data
  4. Auditability
  5. Production controls

Authentication

Authorization

Authorization must be evaluated at the resource boundary:

text
authenticated user
        │
        ▼
project membership / role
        │
        ▼
issue/project action

Do not rely only on UI controls for authorization.

Sensitive data

Do not expose:

  • passwords/password hashes
  • access tokens
  • refresh tokens
  • service credentials
  • private integration credentials
  • internal stack traces

Auditability

Issue changes that materially affect workflow should be attributable to a user or service actor where the project supports audit history.

Production controls

Use:

text
HTTPS
secure cookies where applicable
CSRF protection where applicable
rate limiting
input validation
least-privilege database credentials
secret management outside source control