Security
ModeratorIM handles messages from community members and connects to messaging platforms, so security and privacy are treated as first-class concerns.
Security model
Section titled “Security model”- Authentication & sessions. A core auth layer handles sign-in and server-side session handling; logout revokes the session server-side, not just client-side.
- Permissions (RBAC). Access is governed by a role-based model — users belong to groups, groups carry roles, and roles grant permissions. Apps never evaluate permissions themselves; they declare what a route requires and the core decides.
- App trust boundary. Apps are path-discovered addons that import only the SDK contract, never the core runtime, and reach it through injected per-request handles. Installing an app is a code-trust decision made by the operator.
- Setup protection. First-run setup is gated by a setup key that the operator must supply out-of-band (it is never pre-filled in the UI), so a freshly exposed install cannot be hijacked by whoever reaches it first.
- Data ownership. ModeratorIM is self-hostable and own-your-files: member data stays in the operator’s own datastore, and the design avoids unintended logging, retention, or egress of it.
Reporting a vulnerability
Section titled “Reporting a vulnerability”Do not report security issues through public GitHub issues, pull requests, or discussions.
Report privately instead:
- GitHub Security Advisories — open a private advisory via the repository’s Security → Report a vulnerability tab (preferred).
- Email — the disclosure address listed in the repository’s
SECURITY.md.
Include the type of issue, the affected component, steps to reproduce or a proof-of-concept, and the impact. You will receive an acknowledgement within a few business days and be kept informed through investigation, an agreed disclosure timeline, and credit (if you wish) once a fix ships.
Status
Section titled “Status”The project is in early development and has not yet published a stable release; until the first
tagged release, security fixes are applied to the development branch. The repository’s
SECURITY.md is the authoritative, up-to-date policy.