Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

API key exposed in client-side JavaScript X)

> We conducted a non-intrusive security review, simply by browsing like normal users. Within minutes, we discovered a Supabase API key exposed in client-side JavaScript, granting unauthenticated access to the entire production database - including read and write operations on all tables.



LMAO

how is this even possible? wtf




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: