Files
ihasvpn/SECURITY.md
jcoffey-dev 02e7993c87 Rename the project to ihasvpn
WGX shares its name with several other WireGuard tools, so the project
becomes ihasvpn, alongside ihasmail.

- Module github.com/Coffey-Labs/ihasvpn, command cmd/ihasvpn, image
  ghcr.io/coffey-labs/ihasvpn.
- Environment variables move from WGX_* to IHASVPN_*. The default database
  is ihasvpn.db, the nftables table is `ihasvpn`, metrics are ihasvpn_*, and
  the session cookie and theme key are renamed, so existing sessions end.
- The mark is the ihasmail cat peeking over the edge of a shield, drawn as
  a vector. docs/brand/generate.py builds the mark, mono mark, wordmarks,
  social card, favicons and app icons from that one drawing.
- The console takes ihasmail's palette: the ihasmail.org teal-navy for dark,
  its contrast-checked light tiers with the site's light accent, received
  traffic in the cat's orange and sent in teal. The wordmark weight and
  font stack follow ihasmail.org.
- Detail values wrap at spaces before breaking inside an address, so an
  IPv6 tunnel address no longer splits mid-number.
- The README history note about the earlier WGX installer is gone with the
  name it explained. Screenshots retaken.
2026-09-12 23:48:36 -07:00

2.0 KiB

Security Policy

Supported versions

Security fixes go to main and the next release. Older releases are not patched.

Reporting a vulnerability

Please do not open a public issue for a security problem. Email johnellisATlinuxDOTcom with what you found, how to reproduce it and what you think the impact is. You will get an acknowledgement within a few days and a fix or a plan before anything is made public.

What ihasvpn does to protect itself

  • The admin UI requires a password (argon2id, 64 MiB, 3 passes) and offers time-based one-time codes with recovery codes. Sessions are random 256-bit tokens stored hashed, HttpOnly, SameSite=Strict, with idle and absolute expiry.
  • Every state-changing request must come from the same origin (Sec-Fetch-Site / Origin are checked in addition to the cookie policy) and carry a JSON body; the first-run setup endpoint stops working the moment a user exists.
  • Login is rate-limited per address and per username, and a failed login for an unknown user takes as long as one for a known user.
  • Responses carry a strict Content-Security-Policy, X-Frame-Options: DENY, Referrer-Policy: no-referrer and, under TLS, HSTS.
  • Peer private keys never appear in list or detail responses; they are only returned through the configuration and QR endpoints, and each view is written to the audit log. The server's own private key never leaves the process.
  • The database file is created mode 0600 and the container image contains no shell tooling beyond what nftables and WireGuard need.

What you must do

  • Do not expose port 51821 to the internet without TLS. Either set IHASVPN_TLS_SELF_SIGNED=true (or IHASVPN_TLS_CERT/IHASVPN_TLS_KEY) or put a TLS-terminating reverse proxy in front and list it in IHASVPN_TRUSTED_PROXIES so client addresses in the audit log are right.
  • Turn on two-factor authentication for every administrator.
  • Keep the /data volume private: it holds every peer's private key.