maksit-gitea-cursor/SECURITY.md
2026-08-26 21:00:11 +02:00

24 lines
1.4 KiB
Markdown

# Security policy
This plugin talks to **your** Gitea instance with **your** personal access token. Treat the token like a password.
## Report a vulnerability
Email **security-reports@cursor.com** if the issue is in how Cursor loads plugins.
For this repository, open a private security advisory on [MAKS-IT-COM/maksit-gitea-cursor](https://github.com/MAKS-IT-COM/maksit-gitea-cursor), or email [commercial@maks-it.com](mailto:commercial@maks-it.com). Do not file a public issue that includes tokens, secrets, or a working exploit.
## What this plugin does
- Sends `Authorization: token …` only to `{GITEA_URL}/api/v1/...`.
- Rejects absolute URLs, `..` path segments, and redirects that leave that API prefix.
- Requires HTTPS except for localhost (override with `GITEA_ALLOW_HTTP=true` on a trusted network only).
- Defaults to a curated toolset. Admin APIs, raw `gitea_request`, Actions secrets, runner tokens, and PAT create/delete are off until you set the matching env flag.
## What you should do
- Create a Gitea token with the minimum scopes you need. Do not grant site-admin unless you also set `GITEA_ENABLE_ADMIN=true` and understand the risk.
- Prefer `GITEA_READ_ONLY=true` for review-only agents.
- Never commit `.env` files or paste tokens into issues, skills, or chat logs.
- Trust self-signed certificates in the OS trust store. This plugin does not disable TLS verification.