Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,8 @@ is available we'll credit you (unless you prefer otherwise) in the release notes

| Version | Supported |
|---------|-----------|
| 1.x | ✅ |
| 4.x | ✅ |
| < 4.0 | ❌ |

## Security model (what this library does and doesn't guarantee)

Expand All @@ -37,6 +38,6 @@ The MongoDB/Express backend (`server/liveselect-mongo.js`) enforces:

**The consumer is responsible for** authentication (`authorize` middleware),
CSRF protection on `POST /create`, rate limiting on `/search`, transport
security (HTTPS), and appropriate database indexes. See `IMPLEMENTATION.md §8`.
security (HTTPS), and appropriate database indexes. See `IMPLEMENTATION.md §9`.
Mounting the router without `authorize` and without `tenantFilter` exposes the
whole collection by design — opt into protection deliberately.