idlescape is unfinished and maintained in spare time. There is no bounty and no promised response time.
Please do not open a public issue for a security problem. Use GitHub's private vulnerability reporting on this repository (Security tab, "Report a vulnerability").
- Anything that lets one account read or change another account's characters, bank or agent tokens.
- Anything that gets around the Firestore rules (
firebase/firestore.rules). - Anything that lets a script escape the Worker sandbox (
web/src/agent/) onto the main thread or into another character's session. - Reaching the engine's management port, or forging an owner assertion, from outside the front server.
- A credential, token or personal address committed to the repository.
- A Firebase web config (API key, app id, sender id) is public by design. Access is controlled by Firebase Auth's authorised domains and by the Firestore rules, not by hiding those values.
change-me-...andplaceholder-...values in the.env.examplefiles are placeholders.
Never in the repository. Locally they are in server/.env, web/.env.local and server/secrets/,
all git-ignored. On a deployed box they are generated by deploy/lightsail/provision.ps1 into a
secrets directory outside the source tree. docs/OPERATIONS.md lists every one and where it is read.
You are responsible for it. Use your own Firebase project, generate your own secrets, review the rules before you open it to anyone, and do not point a fork at the author's project or host.