derek
@derek
Not sure if this was even the issue, but a friendly reminder out there for folks (including myself): regularly audit what environment variables appear in client-side code. NEXT_PUBLIC_*, for instance. Vibe coding is really, really bad at this.
3 replies
0 recast
10 reactions
Arti Villa
@artivilla.eth
Can you just provide a prompt that I can ask my AI to check all the security issues that are mini-app specific?
1 reply
0 recast
0 reaction
Arti Villa
@artivilla.eth
Can you further explain this? Next public is supposed to be on the client side. How was an attacker able to override it? If you wanna share a code sample, please do so.
1 reply
0 recast
0 reaction
headless horsefacts
@horsefacts.eth
good advice
0 reply
0 recast
2 reactions