Skip to content

fix: remove hardcoded secret in App.jsx (CWE-798) - #286

Closed
anupamme wants to merge 1 commit into
Paroxity:mainfrom
anupamme:fix-repo-framehub-cwe-798-firebase-api-keys
Closed

anupamme wants to merge 1 commit into
Paroxity:mainfrom
anupamme:fix-repo-framehub-cwe-798-firebase-api-keys

Conversation

@anupamme

Copy link
Copy Markdown

Two complete Firebase project configurations with API keys are hardcoded directly in the client-side React application source. These credentials compile into the production JavaScript bundle and are trivially extractable by any user via browser DevTools. The exposed keys grant direct access to Firebase Auth, Firestore, Storage, and Analytics for both production projects. The affected code is src/App.jsx:14. This change is the fix I would apply.

Reference: CWE-798

What changed

  • src/App.jsx

Verification

No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
@kaedendev kaedendev closed this Sep 23, 2026
@kaedendev

Copy link
Copy Markdown
Member

This is a standard Firebase configuration object that is safe and necessary to ship to the frontend.

@anupamme

Copy link
Copy Markdown
Author

One clarification on the original security classification: Firebase Web API keys are client-side configuration values and are expected to be present in the browser bundle, so moving them to VITE_* variables does not make them secret.

The change still has value as configuration hygiene and avoids committing project-specific Firebase configuration directly into App.jsx, but I don’t want to overstate the security impact as CWE-798.

If there is a concern about unauthorised Firebase access, the relevant follow-up would be to review the Firebase Auth/Firestore/Storage rules and API-key restrictions, and rotate the keys if they have actually been exposed to abuse.

I’m happy to revise the PR description/commit accordingly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants