firebase / firebase/quickstart-js
Security issues with exposing API credentials in firebase-messaging-sw.js?
Open
- Dominant language
- TypeScript
- Stars
- 5.4k
- Forks
- 3.7k
- Avg merge
- 2d 13h
- Merged PRs (30d)
- 6
Description
Are there not any security issues with exposing API credentials in firebase-messaging-sw.js?
Considering it is public and accessible via the console, Applications > Service Workers. (Deploying on a 3rd party hosting service also so automatic initialization is not an option there.)
Contributor guide
Assessment
This issue has not been assessed yet.