Skip to content

Security: echoomegaprime/echo-document-manager

SECURITY.md

Security policy

Echo Document Manager is a multi-tenant Cloudflare Worker (Hono, D1 + KV + R2) storing actual tenant document content (in R2) plus Stripe billing metadata.

Fixed in this consolidation pass

  1. The auth middleware exempted every GET request unconditionally, not just the intended public ones. The repo already has a correctly-designed, token-gated /shared/:token mechanism for deliberate public sharing -- but the blanket c.req.method === 'GET' exemption meant every other GET route was reachable with zero credentials too, given only a guessable id. This is more severe than a metadata-only exposure: /files/:id/download served real file bytes from R2, not just a database row. Also exposed: /tenants/:id, /folders, /files, /files/:id/versions, /files/:id/comments, /shares, /trash, /activity, /analytics/overview, /plans/:tenant_id. Narrowed the exemption to the routes actually meant to be public: /health, /status, /shared/* (its own token gate), /webhooks/stripe (its own HMAC signature check).
  2. Timing side-channel in the credential check. The API key comparison used raw key !== c.env.ECHO_API_KEY. Replaced with a constant-time timingSafeEqual. (The existing Stripe webhook signature check, verifyStripeSignature, was already constant-time -- an XOR-accumulator loop -- and was left unchanged.)

Repo hygiene fixed alongside the security work

The repo had no tsconfig.json and no typescript devDependency at all -- it could not be typechecked as it stood. Added both, matching the same Hono + D1 + KV(+ R2) shape used by sibling repos in this consolidation campaign.

Known, not fixed: npm audit findings are all dev-tooling transitives

npm audit reports 8 vulnerabilities (undici, ws) via wrangler/miniflare's dependency tree -- local dev-server/build tooling, never shipped in the deployed Worker bundle. Fixing requires an unverified major wrangler bump. Same disposition as the identical finding on echo-compliance-auditor and echo-lms earlier in this consolidation campaign.

Supported version

Security fixes target the current main branch. Historical commits are retained for evidence and are not patched in place.

Report a vulnerability

Do not open a public issue for a suspected vulnerability. Send a private report to security@echo-op.com with:

  • affected endpoint and exact revision;
  • reproduction steps and expected impact (this service stores real tenant document content and Stripe billing metadata -- treat any auth-boundary issue as high severity, especially anything touching /files/* or /shared/*);
  • safe contact details for follow-up.

Never include a live ECHO_API_KEY, STRIPE_SECRET_KEY, or STRIPE_WEBHOOK_SECRET in a report.

There aren't any published security advisories