-
Notifications
You must be signed in to change notification settings - Fork 0
Security
Full reasoning in docs/09-security.md.
| Default | Change to |
|---|---|
ALLOW_ANON_TENANT=1 |
0 |
SESSION_SECRET=dev-only-insecure-secret |
A long random value |
| No rate limiting | A limiter in front of /api/ask
|
Anything prefixed NEXT_PUBLIC_ is compiled into the browser bundle in plain
text. Build the app and grep the bundle for the value once; nobody forgets after
seeing it.
No variable in this repository carries that prefix. Every provider call happens in a route handler or a script.
A chunk is a row. A row a user must not read must not be retrievable.
Filter in the WHERE clause, before ranking. Retrieving everything and filtering
afterwards has already put the data in your prompt, then in the model's output,
then in your logs.
The tenant comes from a signed session cookie, never from the request body. A client-supplied tenant id is not access control.
Your own documents are untrusted input. A PDF containing "ignore previous instructions" is an attack delivered through step 1 and executed in step 7. Nobody typed it into the chat box.
Partial mitigations, all present here: explicit CONTEXT delimiters, a system
prompt rule that context is data rather than instruction, and an answer audit
that flags uncited answers and citations to sources that never existed.
None is complete. Trust a document exactly as much as you trust its source.
Demonstrate it in class. Index a document containing an instruction, watch an unguarded system obey it, add the delimiters, watch it stop.
Never innerHTML. The text you are rendering came from a file, and the file came
from somewhere. This repository builds text nodes and anchors.
Every request costs two upstream calls. An unauthenticated /api/ask is somebody
else's inference budget. Rate limit, cap max_tokens, cap the context, cache
embeddings, reject over-long questions.
MIT · Copyright (c) 2026 Prof. Etemi Joshua Garba · No permission required to adopt, edit, refactor or teach from these materials.
Getting started
Decisions
Running it
Reference