If you discover a security vulnerability in this integration, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, use GitHub's private vulnerability reporting so the report stays confidential while it's investigated.
Include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
You will receive an initial response within 48 hours. We will work with you to understand and address the issue before any public disclosure.
This integration communicates with Ajax Systems cloud servers using the same protocol as the official mobile app. Security concerns may include:
- Credential handling and storage
- Network communication security
- Local file access (photo storage)
- FCM push notification handling
Only the latest release is supported with security updates.
These are known, accepted design constraints rather than open issues. They are documented here so users can reason about the integration's security posture.
The Ajax HTS binary protocol (api/hts/) frames are wrapped in AES-128-CBC using
a fixed key and IV that are constants mandated by the protocol; integrity is a
non-cryptographic CRC-16. This inner layer therefore provides no meaningful
confidentiality or integrity on its own. Real protection comes from the TLS
tunnel the HTS connection runs over (ssl.create_default_context(), full
certificate validation). An attacker would have to defeat TLS first; the static
AES layer cannot be changed without breaking compatibility with Ajax hubs.
Push notifications use firebase-messaging, an independent open-source
implementation of the FCM client protocol, not a Google-supported library. Push is an optional feature: if the
library is missing or Google changes the FCM protocol, the integration logs a
warning and continues without push (polling still works). Treat push delivery as
best-effort rather than a guaranteed channel.
The Firebase Web/Android API key bundled in the public Ajax cobranded apps is a
public client identifier shipped inside the published app package, not a secret. It is
allowlisted in .gitleaks.toml for that reason.