mirror of
https://github.com/MAKS-IT-COM/maksit-gitea-cursor.git
synced 2026-09-29 20:48:10 +02:00
24 lines
1.4 KiB
Markdown
24 lines
1.4 KiB
Markdown
# Security policy
|
|
|
|
This plugin talks to **your** Gitea instance with **your** personal access token. Treat the token like a password.
|
|
|
|
## Report a vulnerability
|
|
|
|
Email **security-reports@cursor.com** if the issue is in how Cursor loads plugins.
|
|
|
|
For this repository, open a private security advisory on [MAKS-IT-COM/maksit-gitea-cursor](https://github.com/MAKS-IT-COM/maksit-gitea-cursor), or email [commercial@maks-it.com](mailto:commercial@maks-it.com). Do not file a public issue that includes tokens, secrets, or a working exploit.
|
|
|
|
## What this plugin does
|
|
|
|
- Sends `Authorization: token …` only to `{GITEA_URL}/api/v1/...`.
|
|
- Rejects absolute URLs, `..` path segments, and redirects that leave that API prefix.
|
|
- Requires HTTPS except for localhost (override with `GITEA_ALLOW_HTTP=true` on a trusted network only).
|
|
- Defaults to a curated toolset. Admin APIs, raw `gitea_request`, Actions secrets, runner tokens, and PAT create/delete are off until you set the matching env flag.
|
|
|
|
## What you should do
|
|
|
|
- Create a Gitea token with the minimum scopes you need. Do not grant site-admin unless you also set `GITEA_ENABLE_ADMIN=true` and understand the risk.
|
|
- Prefer `GITEA_READ_ONLY=true` for review-only agents.
|
|
- Never commit `.env` files or paste tokens into issues, skills, or chat logs.
|
|
- Trust self-signed certificates in the OS trust store. This plugin does not disable TLS verification.
|