This document defines the security standards and requirements for all contributors and maintainers of the aricie project.
| Version | Supported |
|---|---|
| 1.x | ✅ Active |
To report a security vulnerability, please open an issue with the security label or contact the maintainers directly. Do not disclose security vulnerabilities publicly via issues or discussions.
We aim to acknowledge reports within 48 hours and provide a timeline for resolution.
All implementations must adhere to the following mitigations:
- Requirement: All external communication must be encrypted (TLS/SSL).
- Action: Use
wss://orhttps://. No cleartext MQTT on public brokers. - Check: Verify
MqttServiceuses secure endpoints (wss://127.0.0.1:8883). - Status: ✅ Production broker uses WSS/TLS. Development (
test.mosquitto.org) is cleartext — do not use with real data.
- Requirement: Device identification must use asymmetric signing (ECDSA/Ed25519).
- Action: Do not use simple SHA-256 hashes for signatures. Implement challenge-response with private key signing on device and public key verification on backend.
- Check: Verify
DeviceCryptoinlib/core/security/uses ECDSA. Audit all signature verification logic. - Status: ✅ Challenge-response infrastructure added (see
docs/core/core.md).
- Requirement: Sensitive user data (tokens, IDs, PII) must be stored in secure hardware-backed storage.
- Action: Use
flutter_secure_storage. Do not useSharedPreferencesfor tokens, sessions, or PII. - Check: Audit all storage calls —
TokenManagermust useFlutterSecureStorage. Local session caching viaSharedPreferencesis acceptable for non-sensitive data only (seeLocalDataSource). - Status: ✅ Tokens migrated to secure storage. Session cache uses
SharedPreferences(cached user ID only).
- Requirement: No secrets in source code.
- Action: Use
--dart-defineat compile time or.envfiles. Ensure.envis in.gitignore. - Check: Audit
main.dart,constants.dart, and all service files for hardcoded keys. - Status: ✅
SUPABASE_URLandSUPABASE_ANON_KEYare passed via--dart-define.supabaseServiceRoleKeyandflespiWorkerTokenremoved fromconstants.dart(2026-06-26).
- Requirement: Production builds must be obfuscated.
- Action: Always use
--obfuscateand--split-debug-infoduring release builds. - Command:
flutter build apk --obfuscate --split-debug-info=build/obfuscation/ - Check: Verify build scripts include these flags. Ensure debug symbols are not distributed.
- Status: ✅ Build command documented in
AGENTS.md.
- Requirement: All trust boundaries (User Input → Backend) must be validated.
- Action: Use strict typing, form validation, and sanitization in UI forms and API controllers.
- Check: Audit form submissions for injection risks. Verify Supabase RLS policies enforce ownership.
- Status: 🟡 In progress — basic validation present, comprehensive audit pending.
- Requirement: Role-based access control (RBAC) with strict perimeter separation.
- Action: Enforce
user_idownership on all database queries. Admin bypass viaprivate.is_admin()SECURITY DEFINER function (queriespublic.users.role, not JWT claims). - Check: Verify RLS policies on all tables. Audit use-cases for permission checks.
- Status: ✅ RLS policies defined in
docs/supabase/init_db.sql. Admin use-cases include RBAC checks.
- Requirement: API abuse prevention for sync and admin operations.
- Action: Implement rate limiting per user and per device.
- Limits: 10 syncs/minute per device, 5 admin actions/minute.
- Status: ✅
RateLimiterimplemented inlib/core/security/.
All administrative actions are logged in the admin_actions table with:
- Admin identity (
admin_id) - Action type and target
- Timestamp and context (
detailsJSONB) - IP address for sync operations
This project follows the OMT_2024_v2 mobile threat model framework. Regular security audits are performed to ensure ongoing compliance.
| Date | Type | Scope | Findings |
|---|---|---|---|
| 2026-06-26 | Secrets cleanup | constants.dart | supabaseServiceRoleKey and flespiWorkerToken removed — both leaked backend-only secrets into the Flutter client. |
| 2026-06-21 | Initial | OMT_2024_v2 full audit | Critical risks in MQTT (cleartext) and DeviceCrypto (naive hashing) identified and mitigated. Infrastructure added for challenge-response and secure MQTT. |