Skip to content

Security Overview

Comprehensive security remediation implemented on 2026-02-18 covering 23 vulnerabilities (4 CRITICAL, 6 HIGH, 8 MEDIUM, 5 LOW).

User visits site
Cloudflare Access
JWT issued
Middleware validates
JWT signature (RS256)
CSRF check
Origin header
Rate limit
Tiered
RBAC check
Endpoint access
User → CF Access → JWT → Middleware (RS256 + CSRF + Rate Limit) → RBAC → Endpoint
LevelData TypeAccess
PublicStatic assets (HTML/CSS/JS)All users
AuthenticatedDashboard summary, basic healthAll authenticated users
Role-BasedRPi stats, UniFi data, operationsAdmin + Operator
Admin-OnlyUser management, audit logs, secretsAdmin only
Physical SecurityTUGA door accessPermission-specific (tuga:door*)