https://github.com/jaebradley/uber-cli/blob/master/src/servi...
https://github.com/jaebradley/uber-cli/blob/master/src/servi...
Obviously, this is a security issue that is pretty much bottom-of-the-barrel-shitty.
My explanation is that I didn't feel like standing up a middleware service to direct traffic through in order to obfuscate the server token. Especially for a tool that I anticipated being used by pretty much only me.
Not a satisfying answer, but thanks for exposing this security flaw - definitely going to add it to my project task queue.
Enforce best practices and don't do that even if it's for something trivial and won't have real world consequences.
$ uber time '123 anywhere st'
No API key found. Please create one using the
instructions at <site> and call 'uber set-key <key>'
$ uber set-key <key> # writes <key> to a file in home dir or a .gitignore location in the repo
Well done!
$ uber time '123 anywhere st' # reads <key> from file, works as you have it
...I think / hope that the worst damage that can be done is hitting Uber's rate limit.
Definitely not defending my decision to include the server token, but I don't think it's the end of the world (just terrible practice).
Why not?