Pachas is built primarily for self-hosting on a private network.
- Keep the app on a trusted LAN by default. The SQLite database is stored in a local file mounted in the app container.
- If you expose Pachas to the public internet, put it behind a reverse proxy
that terminates HTTPS. Set
COOKIE_SECURE: "true"; do not expose port 3000 directly over plain HTTP. - The first account created becomes the site administrator. Create it on a
trusted network, then set
ALLOW_REGISTRATION: "false"after the intended accounts have been created.
- Set
SESSION_SECRETto a random value (openssl rand -hex 32). It is required; rotating it invalidates all existing sessions. - Keep the SQLite database file and its backups private.
DATABASE_PATHcan be used to choose its location inside the container. - Keep
.envprivate and never commit it. Commit placeholders in.env.example, never real credentials or secrets. - Keep the app and its dependencies up to date, and maintain protected backups of the SQLite database.
- Please do not post exploit details in a public issue.
- Use GitHub's private vulnerability reporting if it is enabled for this repository. Otherwise, open an issue with minimal, non-sensitive details and ask to coordinate privately with the maintainer.
- Include reproduction steps and impact in the private report so the issue can be assessed and fixed quickly.
- Never include passwords, session cookies,
.envcontents, or database dumps in issues or logs shared publicly. - Rotate any key, password, or token that is accidentally exposed.