Please report security issues privately via GitHub Security Advisories rather than opening a public issue. Include what you found, how to reproduce it, and what an attacker could do with it. You'll get a response as soon as possible, and a fix will be released before details are published.
ADMIN_TOKENis the single admin credential. Keep it long and random, put TLS in front of the app, and setSECURE_COOKIES=1— see the going-live checklist.- Server ingest API keys are stored only as SHA-256 hashes; a leaked database or backup does not expose usable upload credentials.
- The app never trusts
X-Forwarded-For/CF-Connecting-IPfrom direct internet connections; see the comments inapps/api/main.go(remoteIP) before changing proxy topology.