Skip to content

Security: damale4/Mia

Security

SECURITY.md

Security

Mia is a client-only PWA: there is no backend, database server, or user accounts. All personal data stays in the browser (IndexedDB) on the user's device.

Reporting issues

If you find a security problem, please open a GitHub issue with a clear description. Do not post live exploit details publicly until a fix is available, if the issue is severe.

What we checked

  • No API keys, tokens, passwords, or private credentials in the repository
  • Backup import validates file size, row count, and schema; blocks __proto__ / constructor keys
  • User-visible strings are escaped before insertion into HTML (esc())
  • Share links encode to-do data in the URL (base64); they are not encrypted — anyone with the link can read them
  • PIN is a local screen lock (SHA-256 hash in IndexedDB), not encryption of stored data
  • HTTP security headers via vercel.json (CSP, X-Frame-Options, nosniff, etc.)

Known limitations (by design)

Topic Note
PIN Convenience lock only; data on disk is not encrypted
Share links Readable by anyone who has the URL
Backup JSON Contains all app data in plain text — treat exports as sensitive
Offline cache Service worker caches static assets; no user data in the cache

Dependencies

  • jsPDF (jspdf.umd.min.js) — bundled minified build for PDF reports

Keep third-party files updated when you bump Mia releases.

There aren't any published security advisories