Hacker Newsnew | past | comments | ask | show | jobs light | darkhn

API key exposed in client-side JavaScript X)

> We conducted a non-intrusive security review, simply by browsing like normal users. Within minutes, we discovered a Supabase API key exposed in client-side JavaScript, granting unauthenticated access to the entire production database - including read and write operations on all tables.


LMAO

how is this even possible? wtf




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact |

Search: