<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.pixelrefraction.com/index.php?action=history&amp;feed=atom&amp;title=RefractSurvey_Security_Notes</id>
	<title>RefractSurvey Security Notes - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.pixelrefraction.com/index.php?action=history&amp;feed=atom&amp;title=RefractSurvey_Security_Notes"/>
	<link rel="alternate" type="text/html" href="https://wiki.pixelrefraction.com/index.php?title=RefractSurvey_Security_Notes&amp;action=history"/>
	<updated>2026-09-16T17:29:08Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wiki.pixelrefraction.com/index.php?title=RefractSurvey_Security_Notes&amp;diff=185&amp;oldid=prev</id>
		<title>Nerdofepic: Created page with &quot;RefractSurvey handles a number of security details on its own, without needing any configuration from you. This page is a plain-language rundown of what it does and why, for anyone curious or evaluating it for their team.  == Logging in ==  Repeated failed login attempts are automatically slowed down &amp;mdash; both for one specific username, and (separately) from one specific visitor &amp;mdash; so guessing at a password isn&#039;t a fast or practical way in. A handful of teammates...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.pixelrefraction.com/index.php?title=RefractSurvey_Security_Notes&amp;diff=185&amp;oldid=prev"/>
		<updated>2026-09-13T13:55:20Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;RefractSurvey handles a number of security details on its own, without needing any configuration from you. This page is a plain-language rundown of what it does and why, for anyone curious or evaluating it for their team.  == Logging in ==  Repeated failed login attempts are automatically slowed down — both for one specific username, and (separately) from one specific visitor — so guessing at a password isn&amp;#039;t a fast or practical way in. A handful of teammates...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;RefractSurvey handles a number of security details on its own, without needing any configuration from you. This page is a plain-language rundown of what it does and why, for anyone curious or evaluating it for their team.&lt;br /&gt;
&lt;br /&gt;
== Logging in ==&lt;br /&gt;
&lt;br /&gt;
Repeated failed login attempts are automatically slowed down &amp;amp;mdash; both for one specific username, and (separately) from one specific visitor &amp;amp;mdash; so guessing at a password isn&amp;#039;t a fast or practical way in. A handful of teammates sharing an office connection and occasionally mistyping a password won&amp;#039;t accidentally lock each other out, since the two limits are tuned differently on purpose.&lt;br /&gt;
&lt;br /&gt;
== Access codes ==&lt;br /&gt;
&lt;br /&gt;
The same kind of protection applies to guessing [[RefractSurvey_Codes|access codes]]: repeated failed attempts from the same visitor are throttled with an increasing wait, no matter which page they&amp;#039;re trying codes from.&lt;br /&gt;
&lt;br /&gt;
== Who can see and do what ==&lt;br /&gt;
&lt;br /&gt;
Every action in RefractSurvey is checked against the current user&amp;#039;s permissions and project access before it&amp;#039;s allowed &amp;amp;mdash; by default, a user can&amp;#039;t see or touch a project they haven&amp;#039;t explicitly been granted access to. See [[RefractSurvey_Permissions_and_Roles|Permissions and Roles]] for the full picture of how that&amp;#039;s organized.&lt;br /&gt;
&lt;br /&gt;
== Uploaded images ==&lt;br /&gt;
&lt;br /&gt;
Anything uploaded to a [[RefractSurvey_Media_Library|Media Library]] is checked to make sure it&amp;#039;s a genuine image file, not just something renamed to look like one. Uploaded files are also stored somewhere that can&amp;#039;t execute code, even if someone found a way to sneak something else past the upload check.&lt;br /&gt;
&lt;br /&gt;
== Backups ==&lt;br /&gt;
&lt;br /&gt;
Importing a [[RefractSurvey_Backups|backup]] file is treated as untrusted input, since a backup could in principle come from somewhere other than your own export. RefractSurvey checks the contents of an imported backup carefully before trusting any of it, rather than assuming a zip file is safe just because it has the right file extension.&lt;br /&gt;
&lt;br /&gt;
== Respondent privacy ==&lt;br /&gt;
&lt;br /&gt;
No IP address is ever stored against a submitted survey response &amp;amp;mdash; see [[RefractSurvey_Responses|Responses]] for more on what &amp;quot;anonymous by design&amp;quot; means in practice.&lt;br /&gt;
&lt;br /&gt;
== Keeping up to date ==&lt;br /&gt;
&lt;br /&gt;
Security fixes ship the same way any other update does &amp;amp;mdash; see [[RefractSurvey_Upgrading|Upgrading]] for how to bring an existing install up to the latest version.&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
&lt;br /&gt;
* [[RefractSurvey_Permissions_and_Roles|Permissions and Roles]]&lt;br /&gt;
* [[RefractSurvey_Codes|Codes]]&lt;br /&gt;
* [[RefractSurvey_Backups|Backups]]&lt;br /&gt;
* [[RefractSurvey_Upgrading|Upgrading]]&lt;br /&gt;
&lt;br /&gt;
[[Category:RefractSurvey]]&lt;/div&gt;</summary>
		<author><name>Nerdofepic</name></author>
	</entry>
</feed>