# Security policy Open Notebook Studio is intentionally a thin localhost client. It does not contain, provision, migrate, or print model-provider credentials. Like every Omarchy shell plugin, it runs unsandboxed inside the user's long-lived Quickshell process. Review the source before enabling it and install only from the canonical repository. ## Supported versions | Plugin | Open Notebook API | Security support | | --- | --- | --- | | 1.x | 1.14.x | Yes | | Earlier or later lines | Untested | No compatibility claim | ## Security boundaries - The client accepts `http://` only for `localhost`, `127.0.0.1`, and `::1`. - A remote service requires HTTPS, the explicit `OMARCHY_OPEN_NOTEBOOK_ALLOW_REMOTE=1` opt-in, and a configured Open Notebook password. - Open Notebook authentication is supported through `OPEN_NOTEBOOK_PASSWORD` or `~/.config/omarchy-open-notebook/password`. The file must be mode `600`, owned by the current user, regular, and not a symlink. - Passwords are never accepted as command-line arguments, so they do not enter shell history or process listings. - Source content, chat content, prompts, search responses, notebook titles, and credentials may exist transiently in helper or shell memory, but are not written by the plugin to its own files or logs. The plugin's own durable state contains only the selected notebook ID in Omarchy shell settings. Content deliberately added to Open Notebook is persisted by Open Notebook itself. - Unauthenticated loopback podcast audio streams directly. Authenticated or remote audio is cached under `${XDG_CACHE_HOME:-$HOME/.cache}/omarchy-open-notebook/audio` because Qt Multimedia cannot attach the required bearer header. `XDG_CACHE_HOME` falls back to `~/.cache` when unset. Directories are mode `700`, files mode `600`, cache keys include the canonical API origin, each file is capped at 512 MB, and total LRU retention is about 1 GB. The cache can be cleared in the panel. - Browser and file-picker processes receive only a desktop-safe environment allowlist; provider, database, and cloud credential variables are excluded. - Uploaded files are limited to 100 MB, API responses to 4 MB, and assembled podcast context to 1,000,000 serialized characters by the client. - Podcast job results are allowlisted: transcripts, outlines, audio paths, and raw provider errors never enter QML. Completion notifications are generic. - Safe settings responses are allowlisted, and a model cannot become a default unless Open Notebook reports its provider and modality as currently available. - Web extraction engines such as Firecrawl or Jina may send page content to the configured extraction service; choosing one is an explicit settings action. - Destructive notebook, source, note, credential, and model operations are not exposed in the compact panel. They remain in the full Open Notebook app. The Open Notebook service itself must also be secured. For a workstation-only deployment, publish ports on `127.0.0.1`, not `0.0.0.0`. If you intentionally serve Open Notebook remotely, enable its password authentication, use HTTPS, restrict CORS, and place it behind an appropriate reverse proxy. Open Notebook's single shared password is basic access control rather than enterprise authentication: it has no users, roles, rate limiting, or session timeout. Do not expose that API directly to the public internet. The plugin targets the Open Notebook 1.14.x API and has been live-tested with 1.14.0. Later API lines require compatibility retesting before use. ## Reporting a vulnerability Use [GitHub private vulnerability reporting](https://github.com/dlpwaters/omarchy-open-notebook/security/advisories/new). Do not open a public issue for a suspected vulnerability, and never include real provider keys, notebook data, chat content, passwords, or authentication tokens. ## Plugin-owned files - `${XDG_CONFIG_HOME:-$HOME/.config}/omarchy-open-notebook/password` — optional authentication file, mode `600` - `${XDG_CONFIG_HOME:-$HOME/.config}/omarchy-open-notebook/config.json` — optional endpoint configuration - `${XDG_CACHE_HOME:-$HOME/.cache}/omarchy-open-notebook/audio/` — bounded protected podcast cache, only when authenticated or deliberately remote playback needs it - Omarchy shell settings — selected notebook ID only Removing the plugin leaves these separate paths intact. Clear the podcast cache from **Tools → Settings** and delete the optional connection files yourself when you intentionally want to erase them.