Achar
Security
Content is often the least protected thing a company owns, and it is frequently the most visible. This page describes what Achar does by default, what it deliberately leaves to you, and where the line between the two is.
By default
- Every asset bucket is private, with public access blocked, ACLs disabled, and encryption at rest. The only principal that can read it is the distribution in front of it.
- Every route but one requires a token. `GET /v1/info` is public on purpose, so a deployment can be asked whether it is up.
- API tokens are stored hashed and compared in constant time. The secret is shown once, at creation, and is unrecoverable afterwards by design.
- A project that does not exist and a project you are not a member of answer the same 403, so the API never confirms which project ids exist.
- Point-in-time recovery is on for every table, and every table and bucket is retained rather than deleted when a stack goes away.
Left to you
A public dataset is public. If a document is in one, its contents are readable by anybody who can reach the API, and no amount of token discipline changes that — the arrangement that protects something is a private dataset and a token that names the dataset it may read.
Asset URLs are unsigned, and that is a decision rather than an oversight: an asset URL is published content that ends up in a document, in an `img` tag, and in somebody else's cache, and a URL that expires breaks all three. The protection is the unguessable key, and the token that had to be presented to learn it.
Reporting
Send anything you find to security@achar.example, with enough detail to reproduce it. We will confirm receipt within one working day and say what we intend to do — including when the answer is that we do not consider it a vulnerability.
