This repository is an internal-style prototype and is not approved for real credentials or operational data in its current form.
- Replace sheet-stored plaintext passwords with a managed identity provider.
- Restrict the Apps Script web-app access setting to the intended audience.
- Enforce authorization on every server function, not only in the browser.
- Define session expiry, revocation, and audit requirements.
- Keep employee, dealer, sales, and target data out of source control and screenshots.
Report suspected vulnerabilities privately to itsmbillah@gmail.com. Do not open public issues containing deployment URLs, credentials, or business data.