Running documents

Security

The security properties a reader provides, and what IDOP does not promise.

The full model is on the security model page and in §17 of the specification. In short:

What a reader guarantees

  • Validation before execution. Nothing runs until the whole package has passed every check. One failure refuses the file.
  • Isolation. Document code runs in an opaque-origin sandbox with no network, no access to the reader’s storage, cookies or interface, and no access to other documents.
  • Declared, granted network access. Only exact origins and methods declared in the manifest, only after consent.
  • Credentials stay with the reader. Keys are injected on the reader’s side and never visible to the document.
  • Explicit saves. The file changes only when the user saves, as a validated new revision.

What it does not guarantee

  • Who made a document. Metadata is self-declared; there are no signatures in 1.0.
  • That content is true. A document can display anything.
  • That granted access is harmless. A document you allow to use a service can use it within the declared limits.
  • That a shared file stays private. Anyone who can open a document can copy it.

Reporting a vulnerability

Write to security@idoplabs.com. See the security page for our disclosure policy.