From f2edd89b6407e974190aa53177e5bf16c3550a03 Mon Sep 17 00:00:00 2001 From: Michael Falk Date: Wed, 17 Jun 2026 12:47:01 -0700 Subject: [PATCH] docs: refresh SECURITY.md for v4 (supported versions + section ref) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Supported versions: 1.x → 4.x (and mark < 4.0 unsupported). - Fix cross-reference: the security model is IMPLEMENTATION.md §9 now (it was renumbered from §8 in the v4 docs consistency pass). Co-Authored-By: Claude Opus 4.8 (1M context) --- SECURITY.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 1f9cb4e..d89d869 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -15,7 +15,8 @@ is available we'll credit you (unless you prefer otherwise) in the release notes | Version | Supported | |---------|-----------| -| 1.x | ✅ | +| 4.x | ✅ | +| < 4.0 | ❌ | ## Security model (what this library does and doesn't guarantee) @@ -37,6 +38,6 @@ The MongoDB/Express backend (`server/liveselect-mongo.js`) enforces: **The consumer is responsible for** authentication (`authorize` middleware), CSRF protection on `POST /create`, rate limiting on `/search`, transport -security (HTTPS), and appropriate database indexes. See `IMPLEMENTATION.md §8`. +security (HTTPS), and appropriate database indexes. See `IMPLEMENTATION.md §9`. Mounting the router without `authorize` and without `tenantFilter` exposes the whole collection by design — opt into protection deliberately.