RSTR is a client-side app plus one small Cloudflare Worker
(workers/order-upload) that accepts order uploads. If you find a
vulnerability — anything that could run script in the studio, read or
tamper with other people's order files, or run up storage on the upload
endpoint — please report it privately.
- Preferred: GitHub → Security → "Report a vulnerability" (private advisory) on this repository.
- Alternatively, reach me via the contact details on d17e.dev.
Please don't open public issues for security reports. You'll get a response within a few days and fixes ship as soon as they're ready. There's no bounty program — this is a one-person art project — but you'll get credit and my sincere thanks.