Resonance is a proof of concept. Only the latest commit on main receives security fixes.
Please do not open a public issue for security problems. Email velazco.joseh@gmail.com with:
- A description of the issue and its impact.
- Steps to reproduce it.
- The commit you tested (
git rev-parse --short HEAD).
You will get an answer within 7 days. Once a fix is available, the issue can be disclosed publicly with credit to the reporter, if desired.
Resonance is meant to run locally, on 127.0.0.1. Keep that in mind when reporting:
- In scope: leaking Spotify tokens or the client secret, session cookie issues, access to another user's data through the API, and unsafe handling of data from Spotify or LRCLIB.
- Out of scope: attacks that require exposing the API to a public network, which is not a supported setup, and vulnerabilities in third-party services (Spotify, LRCLIB, Hugging Face). Report those to their owners.
SPOTIFY_CLIENT_SECRETlives only inbackend/.env, which is gitignored.- Spotify access and refresh tokens are stored in the local SQLite database, which is also
gitignored. Delete
backend/data/app.db(path set byAPP_DB_PATH) to remove them. - If you commit a secret by mistake, rotate it in the Spotify developer dashboard right away. Removing it from history is not enough.