Please report security problems privately. Do not open a public issue, discussion or pull request about them.
Use GitHub's private reporting: on this repository's Security tab, choose Report a vulnerability (https://github.com/pokle/glidecomp/security/advisories/new). Only the maintainers can see the report.
A useful report says:
- what you found, and where (a URL, an endpoint, or a file and line);
- how to reproduce it;
- what an attacker could do with it.
Test only against your own account and your own competitions. Do not read, change or delete anyone else's data, and do not run anything that degrades the service for others.
glidecomp.com, including its API underglidecomp.com/api/- preview deployments under
*.glidecomp.pages.dev - the code in this repository
Fixed findings are listed in docs/security-review.md once the fix is deployed.