Security

A high-level look at how Aurora protects your server, its members and its data. Details for administrators are in the security documentation.

Signing in

The dashboard signs you in with Discord OAuth 2.0 using PKCE and asks only for your identity and your server list. Aurora never sees your Discord password. The access token is used once and revoked. Your session is an opaque random id in a secure, HttpOnly cookie, stored hashed on the server, and it expires after 8 hours idle or 7 days in total. Signing out ends it at once.

Authorization

Who may change what is decided on the server, against live Discord data, on every request, with the same policy the bot's commands use. Being able to see a server is not enough: you need to be the owner, a Discord Administrator or hold an Aurora permission group. The list of servers shown after sign-in is only a hint. A server you cannot manage looks the same as one that does not exist.

Protected changes

  • Every change needs a per-session CSRF token and a matching origin.
  • Requests are validated against strict schemas; unknown fields are refused.
  • Rate limits apply, and every channel, role and member id is checked against the authorized server.
  • Every change is audited with the member who made it and where it came from.
  • The pages ship strict security headers, including a nonce-based content security policy.

Bot Control

Messages are sent by the bot process, not by the browser. The dashboard never receives or controls the bot token. Only authorized administrators can use it, only in channels they could post in themselves, and a mention of everyone, here or a locked role needs an explicit switch, a confirmation and the matching Discord permission. Text that merely contains @everyone pings nobody. Actions that the bot does not start within a minute expire instead of being sent late.

Secrets

Credentials live only in the server environment. They are redacted from logs on a best-effort basis and are never sent to the browser or shown on this website. This website itself holds no secrets.

Data protection and privacy

Members can view, export and delete their own data, and the data Aurora keeps is classified table by table. See the privacy page.

Reporting a vulnerability

Please report a suspected vulnerability privately to Aurora's maintainers and do not post it publicly. Include steps to reproduce. Expect an acknowledgement within a few days. A dedicated contact address is not published yet, so use the channel you already have with the maintainers.

This page does not describe internal infrastructure, and it is not an exhaustive list of controls.