The server side of GameAP has been audited against the OWASP Application Security Verification Standard (ASVS), an open list of specific, verifiable security requirements, from how passwords are stored to how uploaded files are handled.
AI agents went through the requirements one by one, and every conclusion was then checked by hand. Each requirement is marked as met, partially met or not met, with references to the code and tests behind it. Both reports are public, including the requirements that are not met yet.
A dedicated test suite, grouped by the OWASP API Security Top 10, checks that users can't reach other people's servers, bypass sign-in or raise their own permissions. It runs on every change.
Every change goes through a code analyzer with security rules (gosec), and tests run against real MySQL, PostgreSQL and Redis.
Every week, sign-in, permission checks and file path handling are fed large amounts of random and malformed input.
Dependencies are checked against the Go vulnerability database (govulncheck) every week and on every change to the main branch. Their versions are pinned with checksums.
Every week, small deliberate bugs are planted in authentication and permission code to make sure the tests catch them.
The code is open on GitHub under the MIT license. Releases come with SHA-256 checksums, and the Docker image runs as a non-root user.
gameapctl can obtain a Let's Encrypt certificate, which the panel then renews on its own. Redirect plain HTTP to HTTPS as well.
TLS_FORCE_HTTPS=true
Administrators get 30 days to set it up, but there's no reason to wait. Ask other users to turn it on too.
This matters most when the panel is open to the internet.
CAPTCHA_PROVIDER
With mutual TLS, the panel accepts connections only from daemons that hold a certificate it issued.
GRPC_REQUIRE_MTLS=true
Use a separate system user for game servers, or run them in Docker or Podman containers.
Turn on permission enforcement as well, so each plugin gets only the access it declares.
PLUGINS_PERMISSIONS_ENFORCE=true
gameapctl generates them during installation. With Docker or a manual installation, set long random values yourself.
ENCRYPTION_KEYAUTH_SECRET
Security fixes ship in regular releases. Watch the GameAP repository on GitHub to get notified about security advisories.
Please don't post vulnerabilities in public issues. Report them privately on GitHub or by email. Reporters are credited in the release notes and the advisory.