4 ms·
There are over 100k firebase authentication files on public GitHub repos
Exibit A: https://github.com/search?q=filename%3Agoogle-services.json&type=Code
also amusing:
https://github.com/search?q=%22delete+google-services.json%22&type=Commits
- rvnx 8y agoEmbedding Firebase and running client-side operations is the concept of Firebase itself, you create an API key for your app and put it in google-services.json. It's a public+non-secret file.
- stackola 8y agoYes you're right, I was under the impression those were more confidential. Still, having 100k firestore url's can't be good, given how hard is is to correctly secure firestore. Also using similar queries, you can try looking for the definitely-not-public serviceAccountKey.json
- villgax 8y agoThis literally comes with every website using Firebase with the configuration in the Javascript, what's you point?
- happppy 8y agoexposed .env files. First result, lol https://github.com/DennisIrimu/instagram/blob/d49ea53281904c477afe37b0c5321ecb5f087576/.env https://github.com/DennisIrimu/instagram/blob/d49ea53281904c...
- quickthrower2 8y agoI’d love to try it out but don’t want to get in trouble!
- infinii 8y agoIt's hard to avoid. My project has a firebaseConfig.js.sample file committed as a reminder to the deployer, they need to create their own. And I put firebaseConfig.js into .gitignore in case a developer is careless.