GitDash
DocsAPI playgroundGitHub
Open GitDash
GitDash Docsv4.7.1
GitHub API playground
  • Introduction
  • Quick start
  • Deployment
  • Configuration
  • Auth modes
  • Access control
  • Caching & rate limits
  • Security model
  • Data sources
  • Feature overview
  • Repositories
  • Repository · Overview
  • Repository · Workflows
  • Repository · Pull requests
  • Repository · Team
  • Repository · Issues
  • Repository · Security
  • Repository · Audit trail
  • Workflow detail
  • Alerts
  • Team insights
  • Contributor & 1:1 prep
  • Cost
  • Reports
  • Org overview & health
  • Settings
  • AI insights
  • Metrics Reference
  • DORA 4 Keys
  • PR Cycle Time
  • PR Lifecycle Health
  • Workflow Overview
  • Performance Tab
  • Reliability Tab
  • Team & People
  • CI & Alert Metrics
  • API Reference
  • FAQ & Troubleshooting
  • Contributing
  • Release Notes
  • Data & privacy
GitHub RepositoryReport an Issue
GitDash Docs

Security model

Your token never reaches the browser

The GitHub token (PAT or OAuth) lives in an encrypted, HTTP-only session cookie that only the server can read. Pages call GitDash's own API; the server calls GitHub.

Request flow

text
Browser ── /api/... ──► proxy.ts
                          │  decrypts the session cookie
                          │  no session        → /login or /setup (pages), 401 (API)
                          │  organization mode → identity + groups, then the route's grant
                          ▼
                     API route ── token from the session ──► GitHub REST API
                          │
                          ▼
                     JSON response (never contains the token)

Protection layers

LayerMechanism
Sessioniron-session (AES-256-GCM); cookie is HttpOnly, SameSite=Lax, Secure in production, 7-day lifetime. SESSION_SECRET must be at least 32 characters.
Sign-inThe session is replaced on every sign-in, so an old session cannot carry over to a new account.
Cross-site requestsState-changing API requests from another origin are rejected; token sign-in only accepts JSON from GitDash's own pages.
Rate limits/api/auth/setup 5 per minute per IP · /api/auth/login 10 per minute · issue creation 5 per hour
Input validationOwner, repo and org parameters are validated before any GitHub call (src/lib/validation.ts).
AuthorizationOrganization mode checks the route's grant on the server for every request (see Access control).
Secrets in responsesAlert destinations (webhooks, email) and AI/email settings are visible to admins only in organization mode.
HTTP headersContent-Security-Policy, HSTS, X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy.
ContainerRuns as the non-root nextjs user on node:20-alpine.
PreviousCaching & rate limitsNextData sources

GitDash v4.7.1 — GitHub Actions Dashboard

Open source on GitHubData & privacyReport an issue