Skip to content
Code Recycle
← Collections

Something private ended up somewhere public

Not a breach anyone detected. A field that crossed a boundary it should not have, in output that looks completely ordinary.

Curated by Code Recycle Editorial

  1. 1

    Your API token is in the page source and you never wrote NEXT_PUBLIC_ anywhere. Measured: the client component never even reads the field, and scanning your JS bundle does not find it.

    Why it's here: Measured: a server-only token in the page source, with no NEXT_PUBLIC_ anywhere.

  2. 2

    Redaction tools report what they removed. Nobody can see what they failed to remove.

    Why it's here: Redaction tools report what they removed. Nobody can see what they missed.

  3. 3
    Rights-Aware ExportComponent✓ from $19

    In an export path, "rights unknown" and "rights permitted" produce the same outcome unless something deliberately makes them differ. The failure is an export that completes successfully and ships material the buyer had no right to receive.

    Why it's here: An export that completes successfully and ships material the buyer had no right to.

  4. 4
    HTTP Cache Semantics (RFC 9111)Component✓ from $29

    A response marked private, stored in a shared cache, serves one user's page to another.

    Why it's here: A private response in a shared cache serves one user's page to another.

  5. 5

    A Twilio Auth Token is exactly 32 lowercase hex characters -- the same shape as an MD5 digest.

    Why it's here: A Twilio Auth Token is 32 lowercase hex — the same shape as an MD5 digest.

  6. 6
    Bidi and Confusable Text SafetyComponent✓ from $29

    Reviewed source code that reads as safe and compiles as something else. The rendering is correct; the human is fooled.

    Why it's here: Source that reads as safe and compiles as something else. The human is fooled.