SwissKnife Docs
Operate SwissKnife

Security

SwissKnife's actual security boundary, HTTP headers, and reporting channel.

SwissKnife is a static application with no backend, user account, or API key. Media never leaves the browser tab. The relevant attack surface is the dependency supply chain, Docker image, GitHub Actions workflows, HTTP headers, and browser runtime.

Container headers

nginx.conf sends, among others:

  • Cross-Origin-Opener-Policy: same-origin
  • Cross-Origin-Embedder-Policy: require-corp
  • Cross-Origin-Resource-Policy: same-origin
  • X-Content-Type-Options: nosniff
  • Referrer-Policy: no-referrer
  • X-Frame-Options: DENY
  • Permissions-Policy: camera=(), microphone=(), geolocation=()
  • a CSP restricted to 'self', with script-src allowing 'wasm-unsafe-eval' and blob:, and img-src / media-src / connect-src / worker-src allowing blob:

The Nginx process does not run as root.

Without COOP/COEP, SharedArrayBuffer is unavailable and FFmpeg WASM cannot load. See Reverse proxy.

Vercel demo headers

The product's vercel.json applies the same families of WASM headers, plus X-Robots-Tag: noindex, nofollow.

Privacy

User files are never uploaded. The FFmpeg core is downloaded from the application's own origin when the first media file is processed, not from unpkg. Canvas image conversions do not trigger that download.

Recommendations

  • use an HTTPS reverse proxy when publishing outside your LAN;
  • do not present a production instance as the “official demo”: use demo.swissknife.lucas-homelab.fr;
  • report vulnerabilities through the Security policy, not a public issue if they weaken the “no uploads” guarantee.

SwissKnife has no JWT, session cookie, or secret environment variable to rotate.

On this page