Passli is engineered with a strict privacy-first, zero-knowledge security posture designed for controlled document sharing without credential exposure.
We actively support and release security updates for the following versions of Passli:
| Version | Supported | Security Maintenance |
|---|---|---|
1.x.x (Current Main) |
✅ | Active Security Patches |
< 1.0.0 |
❌ | Deprecated |
-
Zero-Knowledge Key Storage:
- Plaintext 8-character Share Keys (
XXXX-XXXX) are generated dynamically using cryptographically secure random sources (secrets.choice). - Plaintext keys are never stored in the database or written to disk logs.
- Keys are hashed with salted PBKDF2-HMAC-SHA256 (
django.contrib.auth.hashers.make_password).
- Plaintext 8-character Share Keys (
-
Binary Digest Integrity:
- Every uploaded vault document is processed through SHA-256 checksum hashing on ingestion.
- Binary digests allow instant verification of document integrity and detect unauthorized alteration.
-
Multi-Tenant IDOR Protection:
- All vault access handlers strictly filter by
user=request.useror authenticated session ID before serving document contents. - Direct object reference tampering is caught at the view boundary with HTTP 404/403 responses.
- All vault access handlers strictly filter by
-
Brute-Force & Rate-Limiting Defenses:
- Failed Share Key attempts trigger structured security logs and increment attempt counters.
- Excess attempts enforce exponential lockouts to defeat automated credential stuffing and key enumeration.
-
Server-Enforced Expiration & Revocation:
- Expiration timestamps (
expires_at) are validated on every recipient request. - When a pass expires or is revoked, access is immediately terminated, and session memory is wiped.
- Expiration timestamps (
If you discover a potential security vulnerability within Passli, please do not open a public issue. Instead, follow our responsible disclosure procedure:
- Send an email with full reproduction steps to:
alinawaz.code@gmail.com - Include the following details in your report:
- Description of the vulnerability and its potential impact.
- Step-by-step instructions or proof-of-concept (PoC) code.
- Affected URLs, endpoints, or parameters.
- Suggestions for mitigation or fix (optional).
- Initial Acknowledgment: Within 24 hours.
- Vulnerability Assessment: Within 48 hours.
- Patch & Release: Within 7 business days for critical vulnerabilities.
We credit all responsible security researchers in our release notes and Hall of Fame.