I found 39 Algolia admin keys exposed across open source documentation sites
31–40 of 62 posts
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#32Re: I found 39 Algolia admin keys exposed across open source documentation sites
#33Earlier quoted context omitted.
[flagged]
If you’re “helping a kid” then I guess I can help you. Help is criticism delivered with a constructive tone. Criticism can be helpful if you look past the tone. If you want to help, you should sound helpful.
Of course, if the goal is just to be right rather than to convince someone else about what's right, how you're saying something doesn't matter, but at that point you've already reached the goal before you started talking to them, so it's worth reexamining what you're actually looking to get out of a conversation at that point.
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#34Re: I found 39 Algolia admin keys exposed across open source documentation sites
#35I have been developing an OpenClaw-like agent that automates exactly this type of attack.
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#36Re: I found 39 Algolia admin keys exposed across open source documentation sites
#37the wildest part is algolia just not responding. you email them saying "hey 39 of your customers have admin keys in their frontend" and they ghost you? thats way worse than the keys themselves imo. like the whole point of docsearch is they manage the crawling FOR you, but then the "run your own crawler" docs basically hand you a footgun with zero guardrails. they could just... not issue admin-scoped keys through that…
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#38Re: I found 39 Algolia admin keys exposed across open source documentation sites
#39Twenty years ago every PHP website had search. We forgot how to do it.
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#40the wildest part is algolia just not responding. you email them saying "hey 39 of your customers have admin keys in their frontend" and they ghost you? thats way worse than the keys themselves imo. like the whole point of docsearch is they manage the crawling FOR you, but then the "run your own crawler" docs basically hand you a footgun with zero guardrails. they could just... not issue admin-scoped keys through that…
Why contact Algolia when it is the users' responsibility to handle their keys? Contact all the users.