Skip to content
YAADMIN
Download

YAADMIN DOCUMENTATION

Security

Authentication, permissions and approvals are separate controls.

PartialSource snapshot · 2026-10-02

Three security boundaries#

  1. Authenticate identity
  2. Check capability permission
  3. Approve exact request

Authentication establishes identity. RBAC controls capabilities and scopes. Approval authorizes one bound execution; it is not a replacement for either identity or permission checks.

Sessions and CSRF#

Web sessions persist with expiry. Cookies use HttpOnly and SameSite=lax; secure behavior depends on configuration/HTTPS. Authenticated mutations require a session-matched X-CSRF-Token. The web API does not have a verified bearer API-key authentication scheme.

Local and AD authentication#

Local hashing uses salted PBKDF2-SHA256 with constant-time verification. AD uses a configured provider/worker and canonical identity mapping. Redacted credential lines limit exact end-to-end reconstruction. Local recovery administrator protections prevent lockout.

RBAC and tools#

Permissions are checked before provider execution and again for approved actions. Deny takes precedence; approval effects can strengthen policy. Dynamic MCP tools follow the same runtime gate. User-specific hiding of denied tools in catalogs is not verified.

Approval and audit#

Approval fingerprints prevent changed-request/replay reuse. Pending state is in memory; audit/history persistence is separate. Security audit masking targets sensitive keys, but this is not a guarantee of comprehensive secret removal or an audit certification.

HTTPS and certificates#

Local CA/server certificate/key generation and certificate download/help exist. HTTPS is not universal across every launch mode. Public-CA issuance, automatic rotation and external trust installation are not verified.

Secrets#

Production protected settings use Windows CurrentUser DPAPI with a protected envelope. Personal MCP records are keyed by owner/server; Codex credentials use a protector. The plaintext protector is a testing helper, not a production fallback.

External integrations and packages#

MCP profiles use configured credentials/transports. Personal credentials fail closed instead of falling back to a shared bearer. read_only metadata is an operator assertion, not a remote behavior audit.

Module validation checks archive and manifest/import contracts but imports arbitrary Python. Ordinary module ZIP signatures and process sandboxing are not verified. Update packages have separate integrity/signature checks.

Rate limiting and errors#

Failed-login throttling defaults to five failures in 300 seconds and is held in memory. Missing authentication returns 401; authorization/CSRF denial returns 403; throttled login can return 429. A distributed/global web API limiter is not verified. Action1 has separate outbound pacing/retry handling.

Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.

Search documentation

Search stays in your browser.