I Found 39 Algolia Admin Keys Exposed Across Open Source Documentation Sites
Last October I reported an exposed Algolia admin API key on vuejs.org.
How Algolia DocSearch worksAlgolia's DocSearch is a free search service for open source docs.
35 of the 39 admin keys came from frontend scraping alone.
What these keys can doNearly all 39 keys share the same permission set: search, addObject, deleteObject, deleteIndex, editSettings, listIndexes, and browse.
If I found 39 admin keys with a few scripts, the real number is almost certainly higher.
57 минут назад @ benzimmermann.dev
infomate
