-
Notifications
You must be signed in to change notification settings - Fork 89
Open
Description
Hello, and thank you for the GitGuardian service that you provide, it is really useful.
I want to point out that you should not auto-detect a Firebase API key as "compromised" since this is not a private key but a public key that any entity should access in order to connect to the Firebase API that was set up. Authentication allows only some/all end-users to access/modify/validate certain parts of it, so the API key is not the one that should be guarded.
https://stackoverflow.com/questions/35418143/how-to-restrict-firebase-data-modification
jonas-jonas, heejongahn, vibrunazo, vandorjw, mohandeblaze and 17 more
Metadata
Metadata
Assignees
Labels
No labels