diff --git a/docs/SECURITY.md b/docs/SECURITY.md index 3f35616af..b1e863825 100644 --- a/docs/SECURITY.md +++ b/docs/SECURITY.md @@ -98,6 +98,10 @@ current dataset has tokens, the endpoints below answer `401` unless the request `/start` replaces the previous tokens, so a run started without them is open, and the next run's users cannot read this one. No endpoint returns the tokens; the broker only compares strings (constant-time) and keeps them in memory. Whoever runs `/start` hands the token to the viewers. +An accepted `/start` also clears what the previous run left readable - its statistics, plots and +buffered images - in the same step that installs the new tokens, so the previous run is never +served under the new tokens, and the new run's name never under the old ones. A refused `/start` +(wrong state, invalid settings) changes nothing. | Endpoint | With tokens set | |----------|-----------------| @@ -123,6 +127,5 @@ users cannot read this one. No endpoint returns the tokens; the broker only comp clear unless a TLS reverse proxy fronts the broker (ยง1); on a facility network this raises the bar from "type the IP" to "capture packets", which is the aim. It does not authenticate users or control, does not touch the ZeroMQ streams (issue #3), and `/status`'s free-text `message` may -still quote a path. A Kerberos / GSSAPI single sign-on through a pass-through reverse proxy remains -the option for sites that want user identity; the viewer's libcurl client (with Kerberos on Linux, -SSPI on Windows) can negotiate against such a proxy. +still quote a path. Datasets of different users within one session are separated by their tokens +alone; there is no long-lived login.