Skip to content

Security: Ricardo-NM/realtime-chat

Security

SECURITY.md

Security Policy

Reporting Vulnerabilities

Please do not report sensitive vulnerabilities through public GitHub issues.

Contact email address: lic.ricardo.nm@gmail.com

Supported Expectations

This repository is a starter/reference implementation. It does not promise enterprise support, guaranteed response times, or managed incident handling.

Current Token Storage

The current frontend stores access and refresh tokens in localStorage. This keeps the example simple and avoids cookie-based CSRF as the primary concern, but it increases exposure if an XSS vulnerability exists.

For real public deployments, migrate refresh tokens to HttpOnly, Secure, SameSite cookies and keep access tokens in memory. Review CORS, CSP, rate limits, logs, dependency updates, PostgreSQL backups, Redis availability, and secret rotation before operating this as a public service.

There aren't any published security advisories