OpenGenesisLINKSecurity
Security
Authentication, Scene Tickets, capabilities and remaining production hardening.
Updated 2026-09-17
Published security state
OpenGenesisLINK 2.0.0-dev includes persistent identities, PBKDF2-HMAC-SHA256 password hashing, hashed bearer sessions, signed Scene Tickets, replay protection and explicit capabilities.
Not production-complete yet
- TLS/mTLS hardening
- key rotation
- distributed replay protection
- mature administrative RBAC roles
- complete abuse controls
Deployment: Admin/API and Scene listeners bind to loopback by default. Development secrets must be replaced before external exposure.
Public wiki rule
Secrets, passwords, private IPs, session tokens, test credentials and internal operational access must not be published in the public documentation.