Skip to content

Security: UltraDD/fitlog-web

Security

SECURITY.md

Security

GitHub Token

FitLog is a static web app. The GitHub Fine-grained Token entered on the settings page is stored in the current browser's IndexedDB and sent directly to api.github.com.

Use a dedicated private repository, grant only Contents read/write access, and choose a short expiration. Never paste the token into an Agent, issue, chat, terminal log, or screenshot.

Anyone who can publish JavaScript to the FitLog domain could read tokens saved under that origin. Review the source and deployment ownership before entering a token. Clear the site's browser data to remove locally stored settings.

Reporting

Do not open a public issue containing credentials or personal training data. Revoke an exposed token immediately in GitHub settings before reporting the problem.

There aren't any published security advisories