Mark resolved issues in security-issues.md
This commit is contained in:
+4
-4
@@ -1,8 +1,8 @@
|
|||||||
# Remaining Security Issues
|
# Remaining Security Issues
|
||||||
|
|
||||||
1. **No rate limiting on `/reauth`** — brute-force possible via export dialog
|
1. ~~**No rate limiting on `/reauth`** — brute-force possible via export dialog~~ ✅
|
||||||
2. **No Content Security Policy (CSP)** header — XSS could leak crypto key from sessionStorage
|
2. ~~**No Content Security Policy (CSP)** header — XSS could leak crypto key from sessionStorage~~ ✅
|
||||||
3. **Crypto key in sessionStorage (extractable)** — necessary for refresh persistence, but XSS can steal it. HttpOnly cookie + service worker is more secure but complex
|
3. **Crypto key in sessionStorage (extractable)** — necessary for refresh persistence, but XSS can steal it. HttpOnly cookie + service worker is more secure but complex
|
||||||
4. **No session rotation** — same token until logout; if leaked, valid for 24h
|
4. ~~**No session rotation** — same token until logout; if leaked, valid for 24h~~ ✅
|
||||||
5. **No 2FA** — opted out of TOTP implementation
|
5. **No 2FA** — opted out of TOTP implementation
|
||||||
6. **Password generator modulo bias** — `c.charAt(arr[i] % c.length)` has slight bias when c.length does not divide 2^32; not practically exploitable
|
6. ~~**Password generator modulo bias** — `c.charAt(arr[i] % c.length)` has slight bias when c.length does not divide 2^32; not practically exploitable~~ ✅
|
||||||
|
|||||||
Reference in New Issue
Block a user