4 ms·
API key exposed in client-side JavaScript X) > We conducted a non-intrusive security review, simply by browsing like normal users. Within minutes, we discovere
by gku 8mo ago
API key exposed in client-side JavaScript X)
> We conducted a non-intrusive security review, simply by browsing like normal users. Within minutes, we discovered a Supabase API key exposed in client-side JavaScript, granting unauthenticated access to the entire production database - including read and write operations on all tables.
- r_lee 8mo agoLMAO how is this even possible? wtf