Security
Authentication, origins, LLM endpoints, import limits, network exposure and private reporting.
Published Docker port
main.py dev and main.py serve listen on 127.0.0.1. Published Compose ports bind to all host interfaces by default.
Use the 127.0.0.1:2507:2507 mapping when the published port must stay on localhost.
Network trust
TraDoc is a self-hosted translator for a trusted private network. It has no application token and no multi-user accounts. Docker on a NAS and serve --host 0.0.0.0 assume that network is trusted.
For Internet access, put TraDoc behind HTTPS and authentication at a reverse proxy.
Origins
Write requests from browsers are restricted to the served application, the intended local proxy or explicit ALLOWED_ORIGINS values.
LLM endpoints
The backend validates destinations and can restrict them with ALLOWED_LLM_HOSTS. Do not accept endpoints from untrusted users: an arbitrary URL can target an internal service.
Imports
TraDoc limits file size, archive entry count and uncompressed size to reduce malicious archive risks. These controls do not remove the need to limit access to the instance.
Internet checklist
- HTTPS reverse proxy.
- Suitable external authentication.
- Explicitly defined origins.
- Firewall: only the proxy is public.
- LLM API and database are not exposed.
- Encrypted backups when document sensitivity requires it.
Supported versions
Security fixes target the latest 0.1.x release and the current main branch. Older releases, other branches and forks are not supported; the deleted historical v1.0.0 tag must not be recreated.
Reporting a vulnerability
Do not open a public issue for an exploitable vulnerability. Use the GitHub private advisory form. Do not contact the maintainer by personal email.
If private reporting is unavailable, open a minimal public issue asking for a private contact channel. Do not attach real documents, provider keys, prompts containing private data or other sensitive details.
Include the affected commit or image tag, deployment method, clear reproduction steps and the expected impact. You should receive an acknowledgement within seven days and an initial assessment within fourteen days.
The reference text remains SECURITY.md.