How can I rotate my API key for Firebase?
I wasn't thinking and committed my project I'm starting to GitHub with my API key in one of my files. According to Google themselves, this isn't inherently dangerous itself but my concern is someone malicious could grab my key and use it in their project, potentially hitting limits on the free plan very quickly. I'm struggling to find out how I can grab a new key, any help? Below is a code snippet of what I exposed.
<script src="https://www.gstatic.com/firebasejs/5.5.8/firebase.js"></script>
<script>
// Initialize Firebase
var config = {
apiKey: "my-key",
authDomain: "my_domain",
databaseURL: "my_db_url",
projectId: "my_project_id",
storageBucket: "my_storage_bucket",
messagingSenderId: "my_sender_id"
};
firebase.initializeApp(config);
</script>
firebase google-cloud-platform
add a comment |
I wasn't thinking and committed my project I'm starting to GitHub with my API key in one of my files. According to Google themselves, this isn't inherently dangerous itself but my concern is someone malicious could grab my key and use it in their project, potentially hitting limits on the free plan very quickly. I'm struggling to find out how I can grab a new key, any help? Below is a code snippet of what I exposed.
<script src="https://www.gstatic.com/firebasejs/5.5.8/firebase.js"></script>
<script>
// Initialize Firebase
var config = {
apiKey: "my-key",
authDomain: "my_domain",
databaseURL: "my_db_url",
projectId: "my_project_id",
storageBucket: "my_storage_bucket",
messagingSenderId: "my_sender_id"
};
firebase.initializeApp(config);
</script>
firebase google-cloud-platform
add a comment |
I wasn't thinking and committed my project I'm starting to GitHub with my API key in one of my files. According to Google themselves, this isn't inherently dangerous itself but my concern is someone malicious could grab my key and use it in their project, potentially hitting limits on the free plan very quickly. I'm struggling to find out how I can grab a new key, any help? Below is a code snippet of what I exposed.
<script src="https://www.gstatic.com/firebasejs/5.5.8/firebase.js"></script>
<script>
// Initialize Firebase
var config = {
apiKey: "my-key",
authDomain: "my_domain",
databaseURL: "my_db_url",
projectId: "my_project_id",
storageBucket: "my_storage_bucket",
messagingSenderId: "my_sender_id"
};
firebase.initializeApp(config);
</script>
firebase google-cloud-platform
I wasn't thinking and committed my project I'm starting to GitHub with my API key in one of my files. According to Google themselves, this isn't inherently dangerous itself but my concern is someone malicious could grab my key and use it in their project, potentially hitting limits on the free plan very quickly. I'm struggling to find out how I can grab a new key, any help? Below is a code snippet of what I exposed.
<script src="https://www.gstatic.com/firebasejs/5.5.8/firebase.js"></script>
<script>
// Initialize Firebase
var config = {
apiKey: "my-key",
authDomain: "my_domain",
databaseURL: "my_db_url",
projectId: "my_project_id",
storageBucket: "my_storage_bucket",
messagingSenderId: "my_sender_id"
};
firebase.initializeApp(config);
</script>
firebase google-cloud-platform
firebase google-cloud-platform
asked Nov 20 '18 at 14:35
JoshJosh
305518
305518
add a comment |
add a comment |
1 Answer
1
active
oldest
votes
While some of these keys can be regenerated from the Firebase console, other keys (such as databaseURL
, projectId
and storageBucket
) can't be regenerated. You will have to create a new project to get all new keys.
1
Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
– Josh
Nov 20 '18 at 14:49
1
As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
– Frank van Puffelen
Nov 20 '18 at 14:57
add a comment |
Your Answer
StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53395331%2fhow-can-i-rotate-my-api-key-for-firebase%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
While some of these keys can be regenerated from the Firebase console, other keys (such as databaseURL
, projectId
and storageBucket
) can't be regenerated. You will have to create a new project to get all new keys.
1
Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
– Josh
Nov 20 '18 at 14:49
1
As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
– Frank van Puffelen
Nov 20 '18 at 14:57
add a comment |
While some of these keys can be regenerated from the Firebase console, other keys (such as databaseURL
, projectId
and storageBucket
) can't be regenerated. You will have to create a new project to get all new keys.
1
Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
– Josh
Nov 20 '18 at 14:49
1
As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
– Frank van Puffelen
Nov 20 '18 at 14:57
add a comment |
While some of these keys can be regenerated from the Firebase console, other keys (such as databaseURL
, projectId
and storageBucket
) can't be regenerated. You will have to create a new project to get all new keys.
While some of these keys can be regenerated from the Firebase console, other keys (such as databaseURL
, projectId
and storageBucket
) can't be regenerated. You will have to create a new project to get all new keys.
answered Nov 20 '18 at 14:45
Frank van PuffelenFrank van Puffelen
228k28373396
228k28373396
1
Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
– Josh
Nov 20 '18 at 14:49
1
As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
– Frank van Puffelen
Nov 20 '18 at 14:57
add a comment |
1
Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
– Josh
Nov 20 '18 at 14:49
1
As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
– Frank van Puffelen
Nov 20 '18 at 14:57
1
1
Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
– Josh
Nov 20 '18 at 14:49
Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
– Josh
Nov 20 '18 at 14:49
1
1
As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
– Frank van Puffelen
Nov 20 '18 at 14:57
As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
– Frank van Puffelen
Nov 20 '18 at 14:57
add a comment |
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Some of your past answers have not been well-received, and you're in danger of being blocked from answering.
Please pay close attention to the following guidance:
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53395331%2fhow-can-i-rotate-my-api-key-for-firebase%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown