yoku is an auth-bearing server. If you find a vulnerability, please report it privately via GitHub's "Report a vulnerability" (Security tab) rather than a public issue. Best-effort response; no SLA — this is a personal project.
Before deploying publicly, read the "Deploying publicly" section of the README.