Security and privacy
Public-sector forms carry personal data and feed case systems. quillflow's design starts from one rule: never trust the browser.
What quillflow does
| Risk | What happens |
|---|---|
| Someone edits the page or sends data directly | Every submission is checked again on the server by the same engine and the same rules. Hidden answers, unknown fields and forged calculated values are dropped or recomputed. |
| A form is used to query systems it should not | The browser can only run lookups the form declares, with exactly the declared parameters and only plain values. URLs and credentials exist only on the server. |
| A made-up value where a real one is required | Search fields can name a verify lookup; the server runs it again on submit. |
| Leaking internals | Connector and handler errors are logged on the server. The browser gets a plain 502 or 500. |
| Personal data in caches | Lookup responses and submissions are sent with Cache-Control: no-store. |
| Double submissions | Idempotency keys: one case per submission, even with retries at the same moment. |
| Oversized or malformed requests | JSON only, 1 MB by default, and lookup values limited in size and type. |
| Script injection through form text | Text is inserted as text, never as HTML. Liquid is limited to a safe set of tags and filters. |
| Slow patterns in rules | Formulas cannot run code. On .NET, pattern matching has a time limit. |
| Circular rules | Found when the form is compiled, and again when it is loaded. |
The web component and the designer need no inline scripts or eval, so both run under a strict
Content-Security-Policy.
What stays your job
- Who may fill in or read what. Put authentication and authorization on the API:
.RequireAuthorization(), orauthenticatein Node. - Connectors decide what data a lookup returns to that user. Return only what the form needs.
- Rate limiting, especially on lookups that search registers.
- Retention and storage of submissions, according to your data-protection rules (GDPR). quillflow hands submissions to your handler and does not store them.
- Publishing: forms are versioned, and a published version must not change. Submissions record the version they were made with.