Skip to content

Security: Stupidoodle/chess-com-api

Security

SECURITY.md

Security Policy

Supported Versions

We officially support the following versions with security updates:

Version Supported
1.0.x
0.x.x

Reporting a Vulnerability

We take security issues seriously. We appreciate your efforts to responsibly disclose your findings.

Direct Reporting

  1. DO NOT create a public GitHub issue for security vulnerabilities
  2. Instead, email your findings to [bryan.tran.xyz@gmail.com]
  3. Encrypt your findings using our PGP key to prevent information leaks:
-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGdAGawBEADtOeu6009IvatA0NAE+Jw7bVGJaIAkIVhxm+Zhw1f/qv4zPDP8
Duf8hSVhvYcuk5LIcLxdQMXxDVyWWPfim476elisXAsDS6xRwvpS5A13wZ28koBu
qmc/mrVydrhPdFJMyE0GwzxPcHKNwi2p7fz6Zvgol/I4+NeNKt6u/PxIREsolRbH
pEFfYYDNGndVvtDcUvXEPsgSGPRb5KXN1xndd85y7YMhlw7Tp0CAdehsbpZIz9XT
NwAex2YyInNKxYH1TvYExGc7rPA/N6yxNf4LN3wvqwogidQKD4e/ZI2s9sfQkp7n
QQ9e4tFfEUlXVh6SIxp8pPLpeR8oShbsnqo15EsP8ookHzfq1O3L8ymMoWpg2wKX
O0tNUSr1u+dIt+D8XCwv+VjqsE8gZcWeihx2aCSKwgba+QDW3Rk2Bb4Um+AgE234
VHvzSiTrqogiTrKk8QMdRT0TqRM72Tl7NzSmkYV6k+6O8Wrg0z7qPdjvgMKo7Ov/
AmbOTGiSCKP39bhnBp2Zig8OeIGhkTRUzTvaJXkfeC4Zoc3Hdvsryq1TSEdMkpy2
y1Y913q9v+riBTpRUzzI1Z29KrktRoxJBrpcLYhdqFO0a4ebzNQ+JF/O9qHXO8RM
uo73YzxwcwVS1BG+8z/8Rg761LLt5GtS5b1d+SyU0hpHk4nmPAcFKRz10QARAQAB
tCVCcnlhbiBUcmFuIDxicnlhbi50cmFuLnh5ekBnbWFpbC5jb20+iQJXBBMBCABB
FiEEBGyhq5ZOnrtxQ5a4+AWNcgFvHycFAmdAGawCGwMFCQWj5QQFCwkIBwICIgIG
FQoJCAsCBBYCAwECHgcCF4AACgkQ+AWNcgFvHyc7SRAAsBR8wtSL9d/DXkD1fNQc
NN/LFX/v0Vou5AwJEfUe0DtOwjwLRxwENV2ED5Et4GuKQ8E+/u3aMtRiZkErSjUW
JXMhOAINMVDkZS9DkVBsNmz5bQ7UyosHkiFPpboeJhkdY8AETm7FrmczYD0wSI0n
OcZfnqneg2E1hUlkb8aP74BV0uJZmY6D+w84BlGSPRr156Kr6ejrZQTEGdEsrmP8
YcHxFnT2l8OtIyL6mXM4IrQaDUCv5UEZA6UxUaW14Rjdc+3Zv59cjxBAHiBpTkDt
P6xNOWymv+G/St/aqZWA6zGUxGIc8d/Y9XtFpsxmd7LSgthSkSQ3wUdumSG/COHd
qiIyRGJExRenhhbEB3TutomcwPb9NeItT5cefG8+AVASarXg1wO5fHQ7dbjiACRG
gG54aLOnNdzBolwEBrOs/GiLGyb+q8d0msv0L1uQPvcPog/8Ra57mcrr3JBLIP1P
YvLFJ6dct81WaJvZqN1+HYfEvoAnKk6sL1inqzDJ1ZLchAaY2/qp1yf88va4661y
3jN5PyzYvK1EQqQiSpeKYZwuFPAS54Zt3Na2BcQ1LeyEy3DtrMM/6K7848oQJCrW
qWJTsw/gskG7jVpFavDw/bNothRj8Mt9ms8nXmgGlQZ2ZpHa9FNvKL4Wn0B2vvsy
NMWC40RFYbOOgBRZZGr9Cf+5Ag0EZ0AZrAEQAO6YmCFibANeylVqzq/Ed+bRvw4s
rXPwvnzs0TrzUU65ixfiPy+xIhCNaVnjVAjAN+vwj23qgEo5gu7M1wqXzad4Y7KN
K3txQiAi3a4J5D7InqKp04gTcHXNPG/ha8uIQ/y7r4I9BYFvv5oJ5ajr8RGzqKfy
w2YkqT/Uq80XgrC7M9pXB1LyKJ7+rq3is6t/1o5rW7YHzLnMWjHepy+WgzW/pdMW
S2i+fExs+6ijn6hLpRGIA4etywtZfuoRB9I2DJ6AqxYqptgCSveSJ2Fq2lbnJwjU
K1LoOTglN8WH2VenQ0ToldiuMLZ62x1yoRwDxHHtZsI4QfeNhxnWu2NG4DOh5/FR
mdurm0khQ/EhRC/XwuN5xM5xuaiRa9qqP2GJNYvFPErSsXh3SskadeJfs8IAe8YI
iabF9RkUmoxxLU5vsMW4iMKikQ32EEYtVXZGdsrjteyN7i0kXKG33TsNyd0IIxYh
vcWXWkzYyalNr1vVx9NzaNMun/m5KxHJu22PCeMy24iRhxDjhylJs0LHQOW2zHbB
SDuTqjslRPYDAFGB6onXOSuNN2pUZail0xmX/GKkouxefef310+vw2NABGCf5HtY
JY0+lnDvWr/xEg7YTrHyhVTjg+AOYKp5GQku4tlG1sNksqgJzmkfTDpEzre01uKN
WV0LodBn6r1xlenlABEBAAGJAjwEGAEIACYWIQQEbKGrlk6eu3FDlrj4BY1yAW8f
JwUCZ0AZrAIbDAUJBaPlBAAKCRD4BY1yAW8fJ9/ZEAC0Y03neTaNttgLDXSunQ83
fo+yX7rlhaN+J/ALFj+5qnmUyWC5Uk8VVmt1HEK0BCuOTTkRXJhmRkVcESFWU/NV
E49JGV3NJeb9xYF1lqGpgHO7FZqryEdP3mascpq7XITEKtXqhEMF+7aJQYPS3Rnq
tdrQkJHIJDZVhQy4AlFcoRFo5Hd9LuEku4tCYmfYmS4So8JOevFX+IpYUzTcs1/b
bU8o3jU37uQ5T5lzFMVJZu98CG0gOWMcgSi/2UvY+qpuBCLQeLURMIeVZ60madue
cuT7aF0biPG0UhaRlb8CcRfFhm0YV+2mhupfEZjF+cgUxR9AbqpMfkS+tWOl+GU8
k2DwCJJxI1pirXI5N0wj0QHUVg0gyBNh4JucSCBTpTvtuXvFPZLdJUQbY+1v393Z
7SzVozjs/jmJBjLJeFK5w8IA5gZ2er/9sISjPICJRafYqY378UU+82idTKpj+tLV
hTm0/wTTWbGMnQk46YaIwRKZR9et8oM69VIVcE2Htd/8/AacHh357c5oOBYJ64Yh
UFlh325w2PofXazPzBxpQ9ezhrUV11y1L1Q5XrAztzB0sXNSDfNGutWYhe3tpP5K
mt69nwpt15MwbLrYkpfGqsanr2KGOC9qRV1N81wLegBl11j5oJkmaHgx8ahvSV/e
FzllxqsQ+glmYXO5qKYOdA==
=9pCx
-----END PGP PUBLIC KEY BLOCK-----
  1. You should receive a response within 48 hours
  2. If you don't receive a response, please follow up via https://www.linkedin.com/in/btr-dev/

What to Include

When reporting a vulnerability, please include:

  • A brief description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Any potential solutions you've considered
  • Whether you plan to disclose this publicly
  • Your contact information for follow-up

What to Expect

  1. Initial Response: Within 48 hours
  2. Status Update: Within 1 week
  3. Vulnerability Fix: Timeline depends on complexity
  4. Public Disclosure: Coordinated with reporter after fix

Security Best Practices

When using the Chess.com API Client, follow these security practices:

  1. Keep Updated

    • Always use the latest version
    • Subscribe to security notifications
    • Monitor our security advisories
  2. Configuration

    # Use secure SSL/TLS settings
    client = ChessComClient(
        verify_ssl=True,
        ssl_version="TLSv1_2"
    )
  3. Rate Limiting

    # Configure appropriate rate limits
    client = ChessComClient(
        rate_limit=300,
        max_retries=3
    )
  4. Error Handling

    # Implement proper error handling
    try:
        async with ChessComClient() as client:
            result = await client.get_player("username")
    except ChessComAPIError as e:
        log_security_event(e)
        raise

Security Features

  1. TLS/SSL Support

    • Enforced HTTPS
    • Modern TLS versions
    • Certificate validation
  2. Input Validation

    • Strict type checking
    • Input sanitization
    • Parameter validation
  3. Rate Limiting

    • Request throttling
    • Concurrent request limits
    • Automatic backoff
  4. Error Handling

    • Secure error messages
    • No sensitive data exposure
    • Proper exception hierarchy

Development Security

  1. Code Review Requirements

    • Security-focused review
    • Dependency analysis
    • Type safety checks
  2. CI/CD Security

    • Automated security scanning
    • Dependency auditing
    • Container scanning
  3. Dependency Management

    • Regular updates
    • Vulnerability scanning
    • Dependency pinning

Vulnerability Disclosure Policy

  1. Timeline

    • Day 0: Initial report received
    • Day 2: Initial response provided
    • Day 7: Investigation completed
    • Day 30: Fix developed and tested
    • Day 45: Fix released
    • Day 90: Public disclosure
  2. Scope

    • API client functionality
    • Authentication mechanisms
    • Data handling
    • Network communication
  3. Out of Scope

    • Chess.com API issues
    • Known rate limiting
    • Theoretical attacks
    • Already reported issues

Security Advisories

We publish security advisories for:

  • Critical vulnerabilities
  • Important security updates
  • Security-related version releases
  • Best practice recommendations

Contact

Attribution

We aim to acknowledge security researchers who help improve our security. Researchers will be credited (with permission) in:

  • Security advisories
  • Release notes
  • Hall of fame

There aren't any published security advisories