OpenGravel is self-hosted software: you run the server, you own the data and
the provider keys it uses. This policy covers the app itself and the public
deployment at ride.henning.rodeo.
- Do not open a public issue for security problems.
- Report privately via GitHub Security Advisories ("Report a vulnerability") or email the maintainer directly.
Please include:
- The affected endpoint, file, and line if known.
- A minimal reproduction (request, payload, expected vs actual behavior).
- Impact and any suggested fix.
You will get an acknowledgement within 3 business days and a fix plan (including whether a coordinated disclosure window is needed).
In scope:
- The Next.js app under
src/(API routes, client code, authentication). - Deployment config under
infra/(Caddy, systemd, compose files). - The routing engines (GraphHopper / Valhalla) only insofar as the app misuses them; upstream engines report through their own projects.
Out of scope:
- API keys and credentials in the operator's own environment (these never belong in the repo — see below).
- The browser's geolocation / device permissions model.
- Third-party services the app calls (OpenFreeMap, Photon, NWS, Overpass, Google Places, OpenRouter, You.com).
- All provider API keys are server-only;
NEXT_PUBLIC_*contains only the non-secret map style URL. - Every public endpoint is rate-limited per caller IP; the reverse proxy must
strip and rewrite client-IP headers (see
infra/caddy/Caddyfile.example). - Optional OpenGravel ID uses real WebAuthn verification with explicit production origin/RP-ID configuration. The compatibility-first rebrand does not silently change existing WebAuthn relying-party identity or stored credentials. Only credential id, public key, and counter are stored; private keys stay with the authenticator. Cookie-backed community and sync mutations require the matching CSRF header.
- Operators should keep the Next origin and router ports firewalled behind their proxy and use real TLS certificates for public deployments.