Do not publish credentials, session tokens, personal messages, or a working exploit in a public issue. Contact the repository owner privately through the GitHub profile and include only the minimum information needed to reproduce the problem.
MAX_TOKEN, MAX_DEVICE_ID, and TG_BOT_TOKEN provide access to personal
accounts or messages. Keep them only in .env or a secret manager, restrict the
file to the service account (chmod 600 .env), and never commit it.
If a secret is disclosed:
- Revoke and recreate the Telegram token with
@BotFather. - End the affected Max web session and obtain fresh Max credentials.
- Replace the values on the host and recreate the container.
- Review logs and repository history for accidental disclosure.
Security fixes are applied to the latest commit on main.