Report security issues privately to the BBTSL maintainers.
Do not open public issues for token, auth, audit, staff action, or API issues.
In scope:
- Discord bot authentication and command handling.
- BBTSL API signing.
- Staff command access.
- Audit and export access.
- Component custom IDs.
Out of scope:
- Spam reports without a security impact.
- Public information already shown by BBTSL.
- Requests for reset commands.
A useful report includes:
- the affected command or file;
- the impact;
- the steps to reproduce;
- the expected access level;
- the observed access level.
Do not include real secrets in a report.