Please report security issues privately via GitHub Security Advisories.
Do not open public issues for security vulnerabilities.
IronBuckets authenticates users against your MinIO cluster. Credentials are validated directly with MinIO and are never stored by IronBuckets.
- Sessions are stored server-side
- Session cookies are
HttpOnlyandSecure(when using HTTPS) - Sessions expire after inactivity
- Always use HTTPS in production
- Use strong MinIO credentials — IronBuckets inherits MinIO's access controls
- Keep dependencies updated — Run
go get -uandnpm updateregularly