Hacker News new | ask | show | jobs
by karthikv2k 4410 days ago
Yes, you are right we can modify our JS and get your keys. This vulnerability is in most of the commercial tools out there too. Thats why it is open sourced so you can run it in your own servers. Running it on your own heroku account is close to zero dollars.
1 comments

Not sure if giving Heroku that access is any better :)