Found a security bug?
Thank you! Please report it privately so we can fix it before anyone can abuse it. Don't open a public issue.
Report on GitHub security@angaara.app
What to include
- What the problem is, and what an attacker could do with it
- Steps to reproduce it, or a proof of concept
- Which part it affects: the web app, the server's
/api/endpoints, or the bot SDK - Your Matrix ID or GitHub username, if you'd like credit
What happens next
| When | What we do |
|---|---|
| Within 7 days | Reply to confirm we got your report. |
| While we fix it | Keep you updated on progress. |
| Within 30 days | Aim to ship a fix for serious issues. |
| Once it's fixed | Credit you in the release notes, unless you'd rather stay anonymous. |
Scope
In scope
- The Angaara app at angaara.app
- Angaara's server endpoints under
/api/: GitHub sign-in, XP, appeals, crash and bug reports - The bot SDK in the Angaara repository
Out of scope
- Matrix homeservers like matrix.org. Report those to the server's operator, for example through the matrix.org disclosure policy.
- Bugs that also exist in upstream Cinny. Report those to Cinny.
- Bugs in matrix-js-sdk, Element Call and other dependencies. Report those to their own projects.
- Spam, social engineering, and denial of service by flooding.
Safe harbor
We won't take action against good-faith research that:
- Only uses accounts you own, or have permission to test with
- Doesn't access, change or delete other people's data
- Doesn't disrupt the service for others
- Gives us reasonable time to fix the problem before you go public
Thanks for helping keep Angaara safe 🔥