Security and data
What the prototypes' server sends, stores and deletes.
Headers
The server sends a content security policy with every response that allows scripts, styles, images and connections from the site itself only, frames from the site and from blob addresses, and no plugins. It also sends HSTS, nosniff, a referrer policy of no-referrer, and noindex.
The login
The deployed site is closed behind basic auth until SITE_GATE is set to off. Without a user name and a password set as secrets, it answers 401 to everyone. The comparison runs in constant time.
What is stored
P6 stores public keys, ciphertext and wrapped keys. P7 stores case numbers, wrapped keys and ciphertext. P8 stores field changes. P9 stores bookings with a name and an email address, and the emails it wrote. P11 stores each question. The server deletes all of it after 7 days.
What is never stored
Private keys, receipt codes, passwords and plain text of the encrypted prototypes.
Previous: Docs and assistant (P11). Next: How the prototypes are checked.