This project is pre-alpha and under active development on main (no tagged
release yet). Security fixes land on main.
Please do not open a public issue for security problems.
Report privately by emailing the maintainers or using GitHub's "Report a vulnerability" (Security → Advisories) on the repository. Include:
- a description and impact,
- steps to reproduce (proof of concept if possible),
- affected version/commit,
- any suggested fix.
We aim to acknowledge within a few days and will coordinate a fix and disclosure timeline with you.
- Never commit credentials.
.envfiles,server/logs/,server/mail/*.json, andserver/firebase/are untracked and gitignored; keep them that way. - Cloudinary credentials live only in
server/.env(CLOUDINARY_CLOUD_NAME/CLOUDINARY_API_KEY/CLOUDINARY_API_SECRET). - A Google OAuth
client_secret_*.jsonand a stray browser profile were previously tracked; they are now untracked, but git history still contains credentials. Rotate and purge perdocs/secrets-rotation.md. - If you believe a secret was committed, rotate it immediately and treat the value as compromised — history rewrites alone are not sufficient.
- Set a strong, unique
JWT_SECRET. - Run behind TLS and set
CORS_ORIGINS/PUBLIC_DOMAINfor your deployment. - Keep
NODE_ENV=productionin production (enables stricter rate limits and errors). - Restrict database network access to the application.