This project is a personal, unofficial fan adaptation. Security reports are accepted against the default branch (main).
Do not open a public issue for a suspected vulnerability.
Preferred path:
- GitHub Security tab → Report a vulnerability (private advisory), if that button is available on this repo.
- Otherwise, contact the maintainer via GitHub: @tuirk.
Please include:
- What you found and how to reproduce it
- Affected files / endpoints if you know them
- Whether you have a suggested fix
You should get an acknowledgement within a few days. If the report is valid, we will work on a fix before any public write-up.
- Auth bypass, account takeover, or data exposure in this app
- Secrets committed to the repo
- Dependency or supply-chain issues in this codebase
- XSS / injection in the Next.js app
- The physical TINYforming Mars game or BoardGameGeek
- Firebase / Google platform issues (report those to Google)
- Social engineering or physical attacks
- Automated scanner dumps with no demonstrated impact
Never commit .env, .env.local, Firebase Admin keys, or GOOGLE_GENAI_API_KEY.
Use .env.example as the template only.
Firebase web config (NEXT_PUBLIC_FIREBASE_*) is client-side by design. Restrict it in the Firebase console (HTTP referrers / authorized domains), and keep Firestore / Auth rules tight. Do not treat the web API key as a server secret.
Optional: set NEXT_PUBLIC_FIREBASE_APPCHECK_SITE_KEY and turn on App Check enforcement for Auth/Firestore in the Firebase console.
Gemini server actions require a verified Firebase ID token from a Google or email account (not guest).
If a secret ever lands in git history, rotate it even after the file is removed.