Security

Found a problem? Tell us privately.

If you think you've found a security vulnerability in Tesria, please don't open a public issue.

Reporting a vulnerability

Say what you found, how to reproduce it, and which version you tested. You'll get a reply, and credit in the release notes if you'd like it.

How Tesria protects your wiki

  • Passwords stored with a slow, modern hash; repeated wrong guesses slowed, then locked out.
  • Two-factor sign-in, recovery codes, and single sign-on with Google, Microsoft or any OpenID Connect provider.
  • A Security tab that raises alerts for administrators, by bell and email, with actions to block, sign out or revoke.
  • An audit log chained so that tampering shows.
  • A one-click check of every dependency against OSV.dev, the database behind GitHub's security advisories.
  • Public reading, registration and embeds all off, or limited, until an administrator decides otherwise.

Tesria has been through two full security reviews before this release, and the gaps that remain are written down in the repository rather than hidden. The security hardening guide covers running it safely on the internet.

This website

tesria.com is static files: no accounts, and nothing you type here is sent anywhere. Visits are counted with Cloudflare Web Analytics, which sets no cookies.