shortn
Docs/Security

Security

What is set on every response, what a password actually achieves, and the two places where a request is refused rather than answered.

No accounts · no analytics · no cookies except an unlock cookie

Response headers

X-Frame-Options: SAMEORIGIN
Set everywhere. The password gate is the one thing here worth framing, and it does not need to be embeddable by other sites.
X-Content-Type-Options: nosniff
Set everywhere. With JSON endpoints returning user-supplied text, this is not optional.
Referrer-Policy: strict-origin-when-cross-origin
Keeps a full path from leaking to a third party in the Referer header when you follow a short link from a page with a slug in it.
Strict-Transport-Security
One year, including subdomains.

Cross-Origin-Opener-Policy was set and then removed. It made same-origin iframes unreadable, and nothing on this site needed it. Leaving it would have broken the tools page for no security gain.

Why preview refuses some addresses

/api/preview fetches an address you give it. Left alone, that is a way to ask a server to reach things only it can reach: a loopback service, or something on a private network behind it.

So the address is checked before the fetch happens, not after:

An address that is merely unreachable is not refused. That comes back 200 with empty fields, because "I could not get there" is an answer and not a failure. If every unreachable address were an error, the endpoint would be a way to test whether a given host exists.

What a password gate does

A gate stops somebody following a link from arriving at the destination without typing a word. Specifically:

What it does not do

A gate is not encryption, and not an authorisation The destination is stored in the clear. Whoever runs the server can read it, and so could anyone who reaches the store. A gate decides whether to show the destination to a visitor; it does not make the destination secret. Do not point a protected link at something that must not be known.

For the same reason, a password is not a claim on who may delete a link. Removal needs no password, because the password protects the redirect from the public, not the record from its owner.

What is not collected