From bd13477fa3bb313d82b3eb014dcf57eda8ca65c9 Mon Sep 17 00:00:00 2001 From: sagitchu Date: Thu, 14 May 2026 00:34:52 +0800 Subject: [PATCH] fix: stop caching sensitive configs in browser --- vite-frontend/src/config/site.ts | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/vite-frontend/src/config/site.ts b/vite-frontend/src/config/site.ts index 0b6b066..49ac542 100644 --- a/vite-frontend/src/config/site.ts +++ b/vite-frontend/src/config/site.ts @@ -307,7 +307,17 @@ export const updateSiteConfig = async (configMap?: Record) => { const resolvedConfigMap = configMap ?? (await getCachedConfigs()); Object.entries(resolvedConfigMap).forEach(([key, value]) => { - configCache.set(key, String(value)); + const normalizedKey = key.trim().toLowerCase(); + + if (SENSITIVE_CONFIG_KEYS.has(normalizedKey)) { + configCache.remove(normalizedKey); + + return; + } + + if (shouldPersistConfigKey(normalizedKey)) { + configCache.set(normalizedKey, String(value)); + } }); const hasAppName = Object.prototype.hasOwnProperty.call(