PageSourceSearch

https://theuxshop.com/assets/js/1ce75a96.ead888d5.js

js theuxshop.com collected 2026-10-06 22:15:28 UTC 8,356 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunktheuxshop=self.webpackChunktheuxshop||[]).push([[1120],{4246:(e,s,i)=>{i.r(s),i.d(s,{assets:()=>c,contentTitle:()=>o,default:()=>d,frontMatter:()=>l,metadata:()=>r,toc:()=>a});const r=JSON.parse('{"type":"mdx","permalink":"/security","source":"@site/src/pages/security.mdx","title":"Security","description":"Security practices and vulnerability reporting for The UX Shop.","frontMatter":{"title":"Security","description":"Security practices and vulnerability reporting for The UX Shop."},"unlisted":false}');var n=i(4848),t=i(8453);const l={title:"Security",description:"Security practices and vulnerability reporting for The UX Shop."},o="Security",c={},a=[{value:"Our security practices",id:"our-security-practices",level:2},{value:"Infrastructure",id:"infrastructure",level:3},{value:"Data handling",id:"data-handling",level:3},{value:"Access control",id:"access-control",level:3},{value:"Reporting vulnerabilities",id:"reporting-vulnerabilities",level:2},{value:"What to report",id:"what-to-report",level:3},{value:"How to report",id:"how-to-report",level:3},{value:"What to expect",id:"what-to-expect",level:3},{value:"What we ask",id:"what-we-ask",level:3},{value:"Security headers",id:"security-headers",level:2},{value:"Browser security",id:"browser-security",level:2},{value:"Questions",id:"questions",level:2}];function h(e){const s={a:"a",code:"code",em:"em",h1:"h1",h2:"h2",h3:"h3",header:"header",hr:"hr",li:"li",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,t.R)(),...e.components};return(0,n.jsxs)(n.Fragment,{children:[(0,n.jsx)(s.header,{children:(0,n.jsx)(s.h1,{id:"security",children:"Security"})}),"\n",(0,n.jsx)(s.p,{children:"The UX Shop is a static site with no database and no user accounts. That architecture limits the attack surface significantly. This page explains what security measures are in place and how to report a vulnerability if you find one."}),"\n",(0,n.jsx)(s.h2,{id:"our-security-practices",children:"Our security practices"}
1),"\n",(0,n.jsx)(s.h3,{id:"infrastructure",children:"Infrastructure"}),"\n",(0,n.jsxs)(s.ul,{children:["\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"HTTPS everywhere"}),": All connections to the site use TLS encryption"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Cloudflare protection"}),": We use Cloudflare for DDoS protection and edge security"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Static hosting"}),": The site is statically generated, reducing attack surface"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"No database"}),": We don't maintain a database that could be breached"]}),"\n"]}),"\n",(0,n.jsx)(s.h3,{id:"data-handling",children:"Data handling"}),"\n",(0,n.jsxs)(s.ul,{children:["\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Minimal collection"}),": We collect only what's necessary to operate"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"No sensitive storage"}),": We don't store passwords, payment info, or sensitive personal data"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Client-side tools"}),": Our tools run in your browser - data doesn't leave your device"]}),"\n"]}),"\n",(0,n.jsx)(s.h3,{id:"access-control",children:"Access control"}),"\n",(0,n.jsxs)(s.ul,{children:["\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Limited access"}),": Only necessary personnel have access to hosting and email systems"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Secure authentication"}),": We use strong authentication for all administrative access"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Regular review"}),": We periodically review access permissions"]}),"\n"]}),"\n",(0,n.jsx)(s.h2,{id:"reporting-vulnerabilities",children:"Reporting vulnerabilities"}),"\n",(0,n.jsx)(s.p,{children:"If you discover a security vulnerability, we appreciate responsible disclosure."}),"\n",(0,n.jsx)(s.h3,{id:"what-to-report",children:"What to report"}),"\n",(0,n.jsxs)(s.ul,{children:["\n",(0,n.jsx)(s.li,{children:"Security vulnerabilities in the site or its infrastructure"}),"\n",(0,n.jsx)(s.li,{children:"Privacy issues with data handling"}),"\n",(0,n.jsx)(s.li,{children:"Ways to access unauthorized content or functionality"}),"\n",(0,n.jsx)(s.li,{children:"Cross-site scripting (XSS), injection, or similar issues"}),"\n"]}),"\n",(0,n.jsx)(s.h3,{id:"how-to-report",children:"How to report"}),"\n",(0,n.jsxs)(s.p,{children:["Email security issues to: ",(0,n.jsx)(s.a,{href:"mailto:[email protected]",children:"[email protected]"})]}),"\n",(0,n.jsx)(s.p,{children:"Please include:"}),"\n",(0,n.jsxs)(s.ul,{children:["\n",(0,n.jsx)(s.li,{children:"Description of the vulnerability"}),"\n",(0,n.jsx)(s.li,{children:"Steps to reproduce the issue"}),"\n",(0,n.jsx)(s.li,{children:"Potential impact assessment"}),"\n",(0,n.jsx)(s.li,{children:"Your contact information (optional, but helpful for follow-up)"}),"\n"]}),"\n",(0,n.jsx)(s.h3,{id:"what-to-expect",children:"What to expect"}),"\n",(0,n.jsxs)(s.ul,{children:["\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Acknowledgment"}),": We'll acknowledge receipt within 2 business days"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Assessment"}),": We'll investigate and assess the severity"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Updates"}),": We'll keep you informed of our progress"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Resolution"}),": We'll work to fix confirmed vulnerabilities promptly"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Credit"}),": With your permission, we'll credit you for the discovery"]}),"\n"]}),"\n",(0,n.jsx)(s.h3,{id:"what-we-ask",children:"What we ask"}),"\n",(0,n.jsxs)(s.ul,{children:["\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Don't exploit vulnerabilities"})," beyond what's necessary to demonstrate the issue"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Don't access other users' data"})," or accounts"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Don't disrupt service"})," for other users"]}),"\n",(0,n.jsxs)(s.li,{children:[(0,n.jsx)(s.strong,{children:"Give us reasonable time"})," to fix issues before public disclosure (typically 90 days)"]}),"\n"]}),"\n",(0,n.jsx)(s.h2,{id:"security-headers",children:"Security headers"}),"\n",(0,n.jsx)(s.p,{children:"We implement security headers to protect users:"}),"\n",(0,n.jsx)(s.pre,{children:(0,n.jsx)(s.code,{children:"Content-Security-Policy: Restricts resource loading\nX-Content-Type-Options: Prevents MIME sniffing\nX-Frame-Options: Prevents clickjacking\nReferrer-Policy: Controls referrer information\nPermissions-Policy: Restricts browser features\n"})}),"\n",(0,n.jsx)(s.h2,{id:"browser-security",children:"Browser security"}),"\n",(0,n.jsx)(s.p,{children:"The site is designed to work with modern browsers' security features:"}),"\n",(0,n.jsxs)(s.ul,{children:["\n",(0,n.jsx)(s.li,{children:"We don't require disabling security settings"}),"\n",(0,n.jsx)(s.li,{children:"We support Content Security Policy"}),"\n",(0,n.jsx)(s.li,{children:"We use secure cookies where cookies are necessary"}),"\n"]}),"\n",(0,n.jsx)(s.h2,{id:"questions",children:"Questions"}),"\n",(0,n.jsxs)(s.p,{children:["For general security questions (not vulnerabilities), email ",(0,n.jsx)(s.a,{href:"mailto:[email protected]",children:"[email protected]"}),"."]}),"\n",(0,n.jsxs)(s.p,{children:["For vulnerability reports, use ",(0,n.jsx)(s.a,{href:"mailto:[email protected]",children:"[email protected]"}),"."]}),"\n",(0,n.jsx)(s.hr,{}),"\n",(0,n.jsx)(s.p,{children:(0,n.jsx)(s.em,{children:"Last reviewed: January 2026"})})]})}function d(e={}){const{wrapper:s}={...(0,t.R)(),...e.components};return s?(0,n.jsx)(s,{...e,children:(0,n.jsx)(h,{...e})}):h(e)}},8453:(e,s,i)=>{i.d(s,{R:()=>l,x:()=>o});var r=i(6540);const n={},t=r.createContext(n);function l(e){const s=r.useContext(t);return r.useMemo(function(){return"function"==typeof e?e(s):{...s,...e}},[s,e])}function o(e){let s;return s=e.disableParentContext?"function"==typeof e.components?e.components(n):e.components||n:l(e.components),r.createElement(t.Provider,{value:s},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.