Skip to content

Security: lappat/farhold-os

Security

SECURITY.md

Security Policy

Scope and threat model — read this first

Farhold OS is built for self-hosted, small-group home use (a GM and their players), not for public-internet multi-tenant deployment. That shapes what counts as a real vulnerability here versus an accepted design tradeoff:

  • Player tokens are not cryptographically hardened secrets. They're shared via a private link (Discord DM, etc.) specifically to keep friction low for a home game — see docs/ARCHITECTURE.md. Guessing a token by brute force is a real risk if the server is exposed directly to the public internet without any additional protection; it's not a risk in a Tailscale-only or LAN-only deployment. If you're exposing this beyond your own network, put a real reverse-proxy auth layer or VPN in front of it — the app itself doesn't do rate-limiting or lockout on failed token attempts.
  • No built-in TLS. nginx.conf in this repo is a plain HTTP reference config. Terminating HTTPS is left to your own reverse proxy setup (or a VPN layer like Tailscale) — this is standard for a self-hosted home tool but worth being explicit about.
  • The GM token grants full access to Antinet and RPOS admin functions, including content marked "confidential" in Antinet. Treat it like any other admin credential.

If your use case is different from "GM + players on a private network or behind a VPN," evaluate the above before deploying — none of it is a bug, but all of it is worth knowing.

Reporting a vulnerability

If you find something that falls outside the accepted tradeoffs above — an auth bypass, a way to read another campaign's data, a code injection path, secrets leaking into logs, etc. — please report it privately rather than opening a public issue:

  • Use GitHub's "Report a vulnerability" button (Security tab → Advisories → New draft advisory) on this repo, if available, or
  • Open an issue titled only Security contact needed with no details, and the maintainer will follow up for a private channel.

Please include: what you found, steps to reproduce, and what you think the impact is. There's no bug bounty (this is a solo/community project) but reports are taken seriously and credited in the fix commit unless you'd rather stay anonymous.

Before deploying: run the audit tool

tools/audit_repo.py checks for hardcoded secrets, private IPs, and leftover campaign-specific data before you push changes to a public fork or share your setup with someone else. It's not a substitute for the guidance above, but it catches the most common self-inflicted mistake (a real token or IP address committed by accident).

python3 tools/audit_repo.py .

Supported versions

This is a young, single-branch project — security fixes land on main only. There's no LTS branch or version support matrix at this stage.

There aren't any published security advisories