# Reporting a security problem with RecipeWiki. # # RFC 9116. Served at https://www.recipewiki.com/.well-known/security.txt # # Expires is mandatory and is a promise, not decoration: a stale file tells a # researcher the contact is probably dead and discourages the report. Renew it # before the date below, and re-check that the address is still monitored. Contact: mailto:support@yarkii.com Expires: 2027-08-12T00:00:00.000Z Preferred-Languages: en Canonical: https://www.recipewiki.com/.well-known/security.txt # Notes for anyone reporting: # # This is a wiki. Anyone signed in can edit any recipe, and every edit is # recorded and reversible — that is the design, not a vulnerability. Content # vandalism is best handled by reverting the page and, if it persists, telling # us at the address above. # # Genuinely useful reports include: reading or writing data that row-level # security should prevent, taking over another contributor's account or session, # script injection through recipe content, and anything that exposes a # contributor's email address, which is published on no page.