Forum Discussion
andrew_recroom
5 years agoHonored Guest
GCP API keys exposed in app
Hey folks, our app recently started failing security vulnerabilities testing due to "GCP API keys exposed in app", implying that somewhere in code is a hardcoded web client API key. However, I haven't been able to locate any such issue in our app. Is there a way to run these security checks locally or get more information on where or what exactly the exposed key(s) are?
I was able to determine that these failures come from some Firebase config files used on other platforms. I can remove those configs from Oculus builds (which don't use Firebase), but that won't actually plug the security hole, as it will still be exposing those keys on the platforms that do use Firebase. Seems like this is a Firebase problem now and not an Oculus one.
1 Reply
- andrew_recroomHonored Guest
I was able to determine that these failures come from some Firebase config files used on other platforms. I can remove those configs from Oculus builds (which don't use Firebase), but that won't actually plug the security hole, as it will still be exposing those keys on the platforms that do use Firebase. Seems like this is a Firebase problem now and not an Oculus one.
Quick Links
- Horizon Developer Support
- Quest User Forums
- Troubleshooting Forum for problems with a game or app
- Quest Support for problems with your device
Other Meta Support
Related Content
- 6 months ago
- 5 years agoAnonymous