Skip to main content
Sign-in is an email and a password for a person in one organization. People you add share that organization’s projects, AWS connection, and GitHub connection.

The session

A browser session uses a cookie that is HttpOnly and SameSite=Lax. In production the cookie is also Secure, so the browser sends it only over HTTPS. JavaScript on the page cannot read the cookie. A request that changes data from the browser also has to present a CSRF token from GET /api/csrf. A request that authenticates with Authorization: Bearer is not a cookie session, so it is not checked with that CSRF token. The token itself is the credential. GitHub webhooks are checked with the signature described on GitHub, not with a session. Signing out ends that session. A person or an organization that has been removed can no longer sign in. A removed email cannot be registered again.

Confirming the email

Sign-up sends a 6-digit code. The code expires in 10 minutes, and five wrong attempts invalidate it. Springwinter stores an HMAC of the code, not the code. Password reset uses the same shape. See Credentials. Google and Microsoft sign-in are not enabled.

People in the organization

Any person in the organization can add another person by email, or remove someone else. You cannot remove yourself. There are no roles and no per-project permission levels. Someone you add can open the same projects, assume the same AWS role through Springwinter, and deploy from the same GitHub installation. The team page shows the names and email addresses of the other people. An added person receives a generated password by email. They can change it after signing in. Changing a password asks for the new password twice. It does not ask for the current password.

API tokens

A person can create an API token for the organization. The secret is shown once. Scripts send it as a bearer token. It can do what a person in the organization can do. Revoke it from Settings → API Tokens when it is no longer used, or if it has been exposed. See Credentials.

What is not a control

An identifier in a URL is not a permission. Every read and every change is checked against the signed-in person and their organization. A resource id from another organization does not open that resource.