Reference

Security Model

How Row-Template protects your server, your subscribers and your branding input — and how to report a vulnerability.

Row-Template runs as root on a server that holds your panel, and it serves a page that shows your subscribers’ data. It is built to fail closed: when something is not exactly as expected, it stops and says why rather than guessing.

Getting the release

  • HTTPS only. Downloads use curl pinned to HTTPS and TLS 1.2 or newer, so a redirect cannot downgrade the connection. Plain HTTP needs an explicit testing switch (RT_ALLOW_INSECURE_URL) and never applies to the default source.
  • Mandatory SHA-256. The release archive must match SHA256SUMS before anything is extracted. There is no flag or variable that skips it.
  • Defence in depth. After extraction, the library checks the page against the archive’s own checksum list, validates its structure, verifies every design against its checksum, and refuses a release whose installer files are incomplete.
  • Safe extraction. Absolute paths, .. traversal, symlinks, hard links and special files are refused before extraction, and the archive cannot set file owners or permissions.
  • Data, not code. An update never runs a script it downloaded: only the already-installed, trusted code performs the update, and the downloaded archive is treated as verified data.

What a checksum does and does not prove is explained in Release verification.

Your input

  • Branding is data. It is stored base64-encoded in config.env, which is read with plain text tools and never sourced or executed. The file is mode 640.
  • Strictly validated. Service names are limited to 120 characters with no control characters; support links must use https, http, tg or mailto, so javascript:, data: or file: links are refused at the door.
  • Safely injected. Values enter the page as JSON-escaped strings inside one fixed block, escaped so they cannot end the script, and the page inserts them as text, never as HTML. A value with a control character stops generation instead of being passed through.
  • Logos by content. A logo is accepted only if its first bytes identify it as PNG, JPEG or WebP — SVG, GIF, HTML and anything else are refused, whatever the file is called. It is capped at 256 KiB, and symlinks are refused, including one swapped in after the check.

Changing files

  • Atomic writes. Every file is written to a temporary name beside its target and renamed into place, so readers see the whole old file or the whole new one.
  • Validate before swap. A new page is generated and structurally validated before it replaces the live one. A failure leaves the live page untouched.
  • Automatic restore. Updates, template switches, branding changes and rollbacks snapshot the current state first and restore it if a later step fails. On PasarGuard and Rebecca, activation snapshots the panel’s settings, and a restore is confirmed by reading them back and comparing them with the snapshot — never assumed.
  • No writes through symlinks. Row-Template refuses to write to, or delete, a path that is a symbolic link.
  • Contained deletes. Old backups are removed only from strictly inside the backups folder, never the folder itself. Uninstall first confirms the directory is a Row-Template installation and refuses system paths outright; it removes the row-template command only if the file is Row-Template’s own launcher.

Your panel

  • Fail-closed detection. A panel counts as installed only when two independent signs of it agree; a half-installed panel is refused rather than guessed at. On a server with several panels, a scripted install must name one with RT_PANEL, and an installation never switches to another panel on its own.
  • Fail-closed checks. Installation refuses a 3X-UI below 3.6.0, or one whose version cannot be read, and Rebecca’s 0.0.x Docker image — which would accept the setting and silently keep serving its own page — before anything is changed.
  • No guessing the database. If the first 3X-UI database found is not a real SQLite file, it is refused rather than replaced by another candidate that might belong to a different installation.
  • The smallest change. On 3X-UI only subThemeDir is ever written, with the service stopped and the result read back. On PasarGuard, one marked block is appended to .env and none of your lines is edited; uninstall returns .env to its exact previous bytes. On Rebecca, two fields of the subscription settings are set, and restored exactly on uninstall.
  • Every value escaped. PasarGuard’s template engine does not escape values by default, so every Row-Template page for PasarGuard and Rebecca wraps its body in an explicit autoescape block: a username or a link remark can never inject markup.
  • No secrets in output. On 3X-UI the live checks read one client’s subscription ID to build a local test request; it is never printed, logged or stored. On PasarGuard and Rebecca no subscription is ever looked up. PasarGuard’s .env — which holds your admin password, JWT secret and database URL — is read only for the two page keys, never printed and never copied into a backup, and no Rebecca database password is ever asked for, read or printed. The manager’s info screen shows only whether a support link is set, not the link.

The served page

  • No third-party requests of any kind; everything is inlined in one file.
  • Subscriber links in the Configuration Explorer stay masked until opened and are never written to the console.
  • The page asks not to be indexed and sends no referrer.
  • Live refresh accepts only a response in the shape the page expects from that panel — the page’s own fields on 3X-UI, the panel’s account record on PasarGuard and Rebecca — and stops on anything else.
  • A PasarGuard application’s import link may not be a javascript:, data:, file: or similar address, and its download link must be a web address; its icon is never loaded.

Reporting a vulnerability

Please report security problems privately, not in a public issue. On the repository, open Security → Report a vulnerability and include the affected version (row-template version), your panel and its version, your operating system, and clear steps to reproduce. Security fixes are released for the latest stable version.

If private reporting is unavailable to you, open a minimal public issue asking a maintainer to enable it — with no exploit details.

Edit this page on GitHubApplies to Row-Template 1.4.0
Esc
↑↓ to navigate↵ to selectEsc to close