Skip to content

Security

ModeratorIM handles messages from community members and connects to messaging platforms, so security and privacy are treated as first-class concerns.

  • Authentication & sessions. A core auth layer handles sign-in and server-side session handling; logout revokes the session server-side, not just client-side.
  • Permissions (RBAC). Access is governed by a role-based model — users belong to groups, groups carry roles, and roles grant permissions. Apps never evaluate permissions themselves; they declare what a route requires and the core decides.
  • App trust boundary. Apps are path-discovered addons that import only the SDK contract, never the core runtime, and reach it through injected per-request handles. Installing an app is a code-trust decision made by the operator.
  • Setup protection. First-run setup is gated by a setup key that the operator must supply out-of-band (it is never pre-filled in the UI), so a freshly exposed install cannot be hijacked by whoever reaches it first.
  • Data ownership. ModeratorIM is self-hostable and own-your-files: member data stays in the operator’s own datastore, and the design avoids unintended logging, retention, or egress of it.

Do not report security issues through public GitHub issues, pull requests, or discussions.

Report privately instead:

  • GitHub Security Advisories — open a private advisory via the repository’s Security → Report a vulnerability tab (preferred).
  • Email — the disclosure address listed in the repository’s SECURITY.md.

Include the type of issue, the affected component, steps to reproduce or a proof-of-concept, and the impact. You will receive an acknowledgement within a few business days and be kept informed through investigation, an agreed disclosure timeline, and credit (if you wish) once a fix ships.

The project is in early development and has not yet published a stable release; until the first tagged release, security fixes are applied to the development branch. The repository’s SECURITY.md is the authoritative, up-to-date policy.