---
title: Security
description: What Sluurp does against the common attacks on web apps, and what is left to you.
section: Operations
order: 5
---

# Security

<p class="lead">Common web attacks, as <a href="https://developer.mozilla.org/en-US/docs/Web/Security/Attacks">listed by MDN</a>, and how Sluurp handles each. Most need nothing from you.</p>

## Cross-site scripting (XSS)

Text is never parsed as markup. JSX and `html` templates insert strings as text, so a name like `<img onerror=…>` renders literally. `javascript:` URLs in `href`, `src`, `action` etc. are neutralised however they're encoded. Strings can't be event handlers: `onclick="…"` is rejected. The same applies to server rendering.

## Cross-site request forgery (CSRF)

Requests are authenticated by the `Authorization` header, never by cookies. Another site can make the browser send a request but can't add the header, so it arrives unauthenticated.

## Clickjacking

HTML pages can't be framed by other sites: all are sent with `X-Frame-Options: SAMEORIGIN` and `frame-ancestors 'self'`. A page meant for embedding can set its own header, which takes precedence.

## Insecure direct object references (IDOR)

Ids are random, but that's not the protection. Every read and write goes through the collection's [rules](/docs/rules), enforced in SQL down to individual fields, so knowing an id grants nothing.

## Manipulator in the middle (MITM)

Serve behind TLS; see [Deploying](/docs/deploying). Once a browser connects over HTTPS, `Strict-Transport-Security` pins it there for a year.

## Server-side request forgery (SSRF)

Outbound requests made on a user's behalf (a function's `fetch`, link previews) can only reach public addresses. Loopback, private ranges and cloud metadata endpoints are blocked, every redirect is re-checked, and the check applies to the resolved IP actually connected to, so DNS rebinding doesn't bypass it. Superusers can allow-list extra hosts for functions.

## Prototype pollution

The server parses JSON into Rust types, which have no prototype. In the browser, island props and RPC results are parsed with devalue, which rejects `__proto__` keys.

## Cross-site leaks

Cross-site referrers are trimmed to the origin (`strict-origin-when-cross-origin`), and MIME sniffing is disabled (`nosniff`).

## Supply chain

Nothing is installed at runtime; the server is a single binary. Packages are [vendored](/docs/vendoring) byte for byte into `vendor/` and served from there, not a CDN, so what runs is exactly what you reviewed and committed.

## Phishing and subdomain takeover

These are about people and DNS, not code. Offer two-factor sign-in (see [Sign-in](/docs/auth)), and delete DNS records when their target server goes away.
