Security
How Aurora protects your server and its members, and how to report a vulnerability.
This page is for administrators who want more detail than the public security overview.
Sign-in and sessions#
Discord OAuth 2.0 authorization code flow with PKCE (S256) and a single-use, hashed
state. Only theidentifyandguildsscopes are requested.The access token is used once and revoked; it is never stored.
Sessions are opaque 256-bit ids in a secure,
HttpOnly,SameSite=Laxcookie, stored hashed in the database. They end after 8 hours idle or 7 days in total.
Authorization#
Rights are checked on the server against live Discord data on every request, using the same policy as the bot's commands: the server owner, Discord Administrators or an Aurora permission group. Manage Server alone is not enough. A server you cannot manage and a server that does not exist look the same.
Changes are protected#
A per-session CSRF token and an origin check on every change; JSON only.
Strict schemas: unknown fields are refused.
Rate limits, and every channel, role and member id is checked against the authorized server.
Every change is audited with the member and the origin.
Browser security#
Pages are served with a nonce-based Content Security Policy, X-Content-Type-Options, frame protection, a strict referrer policy and HSTS. The dashboard does not inject raw HTML.
Bot Control#
The bot process sends messages; the dashboard never holds the bot token. Mentions are explicit, requests expire if the bot does not start them within a minute, and audit entries never contain message text. See Bot Control.
Secrets#
Secrets live only in the server environment. Token- and credential-shaped text is redacted from logs on a best-effort basis, and errors name the variable and the rule, never the value.
Reporting a vulnerability#
Report a suspected vulnerability privately to Aurora's maintainers; do not open a public issue. Include steps to reproduce. Expect an acknowledgement within a few days. A dedicated contact address is not published yet; use the channel you already have with the maintainers.