Skip to main content

Security model

  • Ownership: ownedGuest() in routes/vms.js is the single gate for every per-server route. Add new per-server routes through it.
  • Node lookup: the node is resolved from /cluster/resources on each request, so live migration doesn't break anything.
  • Tasks: users can only poll task IDs recorded in the tasks table for them.
  • Console: console sessions are single-use, expire after 30 seconds, and are bound to the user who created them.
  • Sessions: httpOnly, SameSite=Strict JWT cookie; the user is re-read from the database on every request so deleted accounts lose access immediately.
  • Rate limits on sign-in, power actions, snapshots and console.
  • Audit log of every sign-in and action, readable at /api/admin/audit.