Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Security policy

Tollgate decides who may spend what, and records what was spent. A flaw that lets work run without being charged, charges twice, bypasses authentication, leaks a credential or its digest, or corrupts the ledger is a security issue.

Reporting a vulnerability

Report privately through GitHub: on this repository's Security tab, choose Report a vulnerability. Please do not open a public issue, pull request, or discussion for a suspected vulnerability.

A useful report says which crate and version or commit is affected, what an attacker controls, and what they gain, with a reproduction if you have one. A failing test against the invariants in INVARIANTS.md is the most direct form.

The report is acknowledged and tracked in the private advisory. A fix is developed there, released, and then disclosed through a GitHub security advisory, crediting the reporter unless they ask otherwise.

Supported versions

Tollgate is pre-1.0. Fixes land on main and ship in the next release of the current 0.x series; earlier releases are not patched.

Scope

In scope: the crates in this repository, including the tollgate-server control plane's authentication, TLS, and authorization. Deployment configuration is the operator's, but documentation that leads to an insecure deployment is in scope; see docs/CONTROL_PLANE_SECURITY.md.

Out of scope: examples/, which demonstrate embedding with demo credentials, and denial of service that requires control of the store or the network path between instances and the server.