Conversation
Automated security fix generated by OrbisAI Security
|
This is a standard Firebase configuration object that is safe and necessary to ship to the frontend. |
|
One clarification on the original security classification: Firebase Web API keys are client-side configuration values and are expected to be present in the browser bundle, so moving them to VITE_* variables does not make them secret. The change still has value as configuration hygiene and avoids committing project-specific Firebase configuration directly into App.jsx, but I don’t want to overstate the security impact as CWE-798. If there is a concern about unauthorised Firebase access, the relevant follow-up would be to review the Firebase Auth/Firestore/Storage rules and API-key restrictions, and rotate the keys if they have actually been exposed to abuse. I’m happy to revise the PR description/commit accordingly. |
Two complete Firebase project configurations with API keys are hardcoded directly in the client-side React application source. These credentials compile into the production JavaScript bundle and are trivially extractable by any user via browser DevTools. The exposed keys grant direct access to Firebase Auth, Firestore, Storage, and Analytics for both production projects. The affected code is
src/App.jsx:14. This change is the fix I would apply.Reference: CWE-798
What changed
src/App.jsxVerification
No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.
Automated security fix by OrbisAI Security