If you discover a security vulnerability in QYVORA Frontend, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, please email: qyvorasec@gmail.com with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Suggested fix (if any)
We will acknowledge receipt within 48 hours and provide a timeline for resolution.
- JWT access tokens stored in-memory only (never localStorage)
- Refresh tokens in httpOnly cookies (browser-managed)
- CSRF double-submit pattern: token in localStorage +
X-CSRF-Tokenheader - Silent token refresh on 401 with automatic retry
- Session hint in localStorage for refresh gating
- DOMPurify for all user-generated HTML content
- CSP headers configured in
netlify.toml:default-src 'self'script-src 'self'object-src 'none'frame-ancestors 'none'
- XSS protection headers enabled
- Referrer-Policy: strict-origin-when-cross-origin
- All API communication over HTTPS
- CORS configuration via backend
- Permissions-Policy restricting browser features (no camera, microphone, etc.)
- No sensitive data in localStorage (only preferences, CSRF token, session hint)
- No API keys in client-side code
- Environment variables prefixed with
VITE_for client exposure .envfiles in.gitignore
| Version | Supported |
|---|---|
| Latest | Yes |
| < Latest | No |
Configured in netlify.toml:
X-Frame-Options: DENYX-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadReferrer-Policy: strict-origin-when-cross-origin