Security
SwissKnife's actual security boundary, HTTP headers, and reporting channel.
SwissKnife is a static application with no backend, user account, or API key. Media never leaves the browser tab. The relevant attack surface is the dependency supply chain, Docker image, GitHub Actions workflows, HTTP headers, and browser runtime.
Container headers
nginx.conf sends, among others:
Cross-Origin-Opener-Policy: same-originCross-Origin-Embedder-Policy: require-corpCross-Origin-Resource-Policy: same-originX-Content-Type-Options: nosniffReferrer-Policy: no-referrerX-Frame-Options: DENYPermissions-Policy: camera=(), microphone=(), geolocation=()- a CSP restricted to
'self', withscript-srcallowing'wasm-unsafe-eval'andblob:, andimg-src/media-src/connect-src/worker-srcallowingblob:
The Nginx process does not run as root.
Without COOP/COEP, SharedArrayBuffer is unavailable and FFmpeg WASM cannot load. See Reverse proxy.
Vercel demo headers
The product's vercel.json applies the same families of WASM headers, plus X-Robots-Tag: noindex, nofollow.
Privacy
User files are never uploaded. The FFmpeg core is downloaded from the application's own origin when the first media file is processed, not from unpkg. Canvas image conversions do not trigger that download.
Recommendations
- use an HTTPS reverse proxy when publishing outside your LAN;
- do not present a production instance as the “official demo”: use demo.swissknife.lucas-homelab.fr;
- report vulnerabilities through the Security policy, not a public issue if they weaken the “no uploads” guarantee.
SwissKnife has no JWT, session cookie, or secret environment variable to rotate.