Skip to content

Security: OneBigHen/switchback

Security

SECURITY.md

Security Policy

OpenGravel is self-hosted software: you run the server, you own the data and the provider keys it uses. This policy covers the app itself and the public deployment at ride.henning.rodeo.

Reporting a vulnerability

  • Do not open a public issue for security problems.
  • Report privately via GitHub Security Advisories ("Report a vulnerability") or email the maintainer directly.

Please include:

  1. The affected endpoint, file, and line if known.
  2. A minimal reproduction (request, payload, expected vs actual behavior).
  3. Impact and any suggested fix.

You will get an acknowledgement within 3 business days and a fix plan (including whether a coordinated disclosure window is needed).

Scope

In scope:

  • The Next.js app under src/ (API routes, client code, authentication).
  • Deployment config under infra/ (Caddy, systemd, compose files).
  • The routing engines (GraphHopper / Valhalla) only insofar as the app misuses them; upstream engines report through their own projects.

Out of scope:

  • API keys and credentials in the operator's own environment (these never belong in the repo — see below).
  • The browser's geolocation / device permissions model.
  • Third-party services the app calls (OpenFreeMap, Photon, NWS, Overpass, Google Places, OpenRouter, You.com).

Security model notes

  • All provider API keys are server-only; NEXT_PUBLIC_* contains only the non-secret map style URL.
  • Every public endpoint is rate-limited per caller IP; the reverse proxy must strip and rewrite client-IP headers (see infra/caddy/Caddyfile.example).
  • Optional OpenGravel ID uses real WebAuthn verification with explicit production origin/RP-ID configuration. The compatibility-first rebrand does not silently change existing WebAuthn relying-party identity or stored credentials. Only credential id, public key, and counter are stored; private keys stay with the authenticator. Cookie-backed community and sync mutations require the matching CSRF header.
  • Operators should keep the Next origin and router ports firewalled behind their proxy and use real TLS certificates for public deployments.

There aren't any published security advisories