trackslash
TRACK-101 P2

Send security reports to [email protected]

0
All issues

Description

The security contact should be [email protected]. Bad Bundle already publishes that address in badbundle.com's own /.well-known/security.txt (bad-bundle-web).

Trackslash currently tells reporters to use [email protected], but trackslash.com has no MX records (checked 2026-09-28), so reports sent there bounce.

Change

  • SECURITY.md (line 5): the reporting address.
  • legal/SECURITY.md (line 10): the policy served at /security.
  • internal/server/ui_site_metadata.go: securityContactAddress, which is the Contact: line in /.well-known/security.txt.
  • internal/server/preview_terms_integration_test.go: the /security case expects the old address. ui_site_metadata_test.go reads the constant, so it follows automatically.
  • CSS: run npm run assets after the Go change and commit app.css if it changed, since Tailwind scans Go files.

Before merging

Check that badbundle.com's Cloudflare Email Routing delivers security@ (a specific rule or a catch-all), for example by sending it a test message.

Same problem, decision needed

Two more contact addresses on trackslash.com also bounce:

The options:

  • Move them to badbundle.com addresses too. Other Bad Bundle apps use [email protected] and [email protected].
  • Turn on Email Routing for trackslash.com, so the existing addresses work.

Recommended: move them in the same PR. Then trackslash.com needs no incoming mail at all, and TRACK-96 only has to set up sending.

Done when

  • Every security contact in the repo, the /security page and security.txt says [email protected].
  • privacy@ and legal@ are handled as decided above.
  • Tests and npm run assets:check pass.
  • A test email to each published address arrives.

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.