Security
Authentication
Sign-in is OAuth only, through Google or GitHub. Rubricary never asks for or stores a password, and there is no password-reset flow to secure because there is no password.
- The browser authenticates with the OAuth provider; the server exchanges that for a session cookie.
- The session cookie (
rubricary_session) is HTTP-only and Secure in production, withSameSite=Lax. It can't be read from client-side JavaScript and isn't sent on cross-site requests. - It lasts 14 days and, in production, is scoped to
.rubricary.com— so a future subdomain shares one session without a migration. - There's a fixed local identity used for development so signed-in screens are reachable without a real OAuth project — it trusts nothing, verifies nothing, and refuses to start at all if it's ever configured in production.
Every "is this the caller's data?" check happens in server code after the session is verified, not in a database policy — there's no row-level security to lean on. Before answering, the server checks the caller's role in the organization that owns the data: committing to a prompt needs membership; publishing, running evals and changing settings need owner or admin; deleting needs owner. An organization's audit trail is visible only to its owners and admins, and anyone else gets a 404, as they do for a private prompt.