okay so this actually happened and i think it's worth sharing because it taught me more about real security than any tutorial ever did.
💀 the callout
we just shipped koda v24 — moved our api key behind a cloudflare worker so bots couldn't steal it from our javascript anymore. felt pretty smart about it tbh.
then ivan annovazzi commented on our architecture article:
"Moving the key behind a Worker fixes the client exposure, but the Worker URL is now sitting in your JS bundle too. What stops a bot from POSTing to it directly and burning the same credits you were losing before?"
and bro. he was RIGHT. 💀
we'd hidden the key but left the door wide open. anyone with the worker url could just... send requests straight to it. drain our groq credits. the whole thing we built the vault to prevent? still possible. just through a different door.
i stared at that comment for like 10 minutes feeling equal parts embarrassed and grateful.
🔧 the fix (layer 1 — shipped same day)
we added an origin lock to the worker. now it checks where every request comes from:
- from
koda-aicodementor.netlify.app? ✅ come on in - from anywhere else? 🚫
{"error":"Forbidden"}get out
literally went to the cloudflare preview after deploying and saw {"error":"Forbidden"} staring back at me. the bouncer is hired. the door is locked.
😅 the mobile editor war
here's the part nobody talks about: i deployed this fix FROM MY PHONE.
the cloudflare web editor on mobile was fighting me the entire time:
- syntax errors jumping from line 63 → 68 → 77 every paste
- auto-format shoving braces onto wrong lines
- minified single-line version lagging the editor into oblivion
i finally won by:
- turning off auto-format
- removing all arrow functions, spreads, and template literals (mobile keyboards corrupt them)
- using
Object.assign()and string concatenation instead
deployed clean. origin lock live. all from a poco c55. constraints breed elegance, bro. 📱
🛡️ what's next (layers 2 & 3)
origin locking stops casual bots. but a determined attacker can spoof headers. so we're not stopping here:
layer 2: cloudflare access / mtls — make spoofing mathematically impossible
layer 3: rate limiting (30 req/min per ip) + groq spend cap ($5 hard limit)
even if someone bypasses layers 1 AND 2, they hit a $5 ceiling instead of an unlimited tab. that's defense in depth.
🧠 what this taught me
build in public or stay vulnerable forever. if ivan hadn't commented, that hole would've sat there until a bot found it at 3am. public scrutiny IS free security auditing.
proxies aren't security. a worker with no auth is just a relay. always ask: who's allowed to call this? what happens when they're not? what's the worst case?
thank your critics. ivan didn't have to comment. he could've just exploited it quietly. instead he gave us the blueprint to fix it. that's a gift. treat it like one.
📨 the reply i posted
@ivannovazzi — shipped. The Worker now checks the Origin header against an allowlist. Any POST from anywhere else gets a hard 403 {"error":"Forbidden"}. Layer 2 (mTLS) and Layer 3 (rate limiting + spend cap) are next. Thanks for the push — this made the stack materially more secure. 🛡️
go read his original comment. then go test koda. the vault is locked now, because a stranger cared enough to tell us it wasn't.
🔗 https://koda-aicodementor.netlify.app/
Top comments (1)
That mind set to take the feedback with open mind is important. I remember you replying to his comment with steps, but still you went back and reviewed it to make sure not missing something, great job!