Skip to content

Security: Scotho/idlescape

SECURITY.md

Security

idlescape is unfinished and maintained in spare time. There is no bounty and no promised response time.

Reporting

Please do not open a public issue for a security problem. Use GitHub's private vulnerability reporting on this repository (Security tab, "Report a vulnerability").

What matters most

  • Anything that lets one account read or change another account's characters, bank or agent tokens.
  • Anything that gets around the Firestore rules (firebase/firestore.rules).
  • Anything that lets a script escape the Worker sandbox (web/src/agent/) onto the main thread or into another character's session.
  • Reaching the engine's management port, or forging an owner assertion, from outside the front server.
  • A credential, token or personal address committed to the repository.

Things that are not secrets

  • A Firebase web config (API key, app id, sender id) is public by design. Access is controlled by Firebase Auth's authorised domains and by the Firestore rules, not by hiding those values.
  • change-me-... and placeholder-... values in the .env.example files are placeholders.

Where real secrets live

Never in the repository. Locally they are in server/.env, web/.env.local and server/secrets/, all git-ignored. On a deployed box they are generated by deploy/lightsail/provision.ps1 into a secrets directory outside the source tree. docs/OPERATIONS.md lists every one and where it is read.

If you host your own copy

You are responsible for it. Use your own Firebase project, generate your own secrets, review the rules before you open it to anyone, and do not point a fork at the author's project or host.

There aren't any published security advisories