Documentation menu

Security

How Aurora protects your server and its members, and how to report a vulnerability.

This page is for administrators who want more detail than the public security overview.

Sign-in and sessions#

  • Discord OAuth 2.0 authorization code flow with PKCE (S256) and a single-use, hashed state. Only the identify and guilds scopes are requested.

  • The access token is used once and revoked; it is never stored.

  • Sessions are opaque 256-bit ids in a secure, HttpOnly, SameSite=Lax cookie, stored hashed in the database. They end after 8 hours idle or 7 days in total.

Authorization#

Rights are checked on the server against live Discord data on every request, using the same policy as the bot's commands: the server owner, Discord Administrators or an Aurora permission group. Manage Server alone is not enough. A server you cannot manage and a server that does not exist look the same.

Changes are protected#

  • A per-session CSRF token and an origin check on every change; JSON only.

  • Strict schemas: unknown fields are refused.

  • Rate limits, and every channel, role and member id is checked against the authorized server.

  • Every change is audited with the member and the origin.

Browser security#

Pages are served with a nonce-based Content Security Policy, X-Content-Type-Options, frame protection, a strict referrer policy and HSTS. The dashboard does not inject raw HTML.

Bot Control#

The bot process sends messages; the dashboard never holds the bot token. Mentions are explicit, requests expire if the bot does not start them within a minute, and audit entries never contain message text. See Bot Control.

Secrets#

Secrets live only in the server environment. Token- and credential-shaped text is redacted from logs on a best-effort basis, and errors name the variable and the rule, never the value.

Reporting a vulnerability#

Report a suspected vulnerability privately to Aurora's maintainers; do not open a public issue. Include steps to reproduce. Expect an acknowledgement within a few days. A dedicated contact address is not published yet; use the channel you already have with the maintainers.