security: remove exposed Cloudinary credentials from client bundle
- Strip NEXT_PUBLIC_ prefix from CLOUDINARY_API_KEY and API_SECRET so they stay server-side only and are never shipped to the browser - Update lib/cloudinary.ts to read the renamed env vars - Remove cloudinary-assets.json from git tracking and add to .gitignore Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
+2
-2
@@ -3,8 +3,8 @@ import { v2 as cloudinary } from 'cloudinary';
|
||||
// Configure Cloudinary with environment variables
|
||||
cloudinary.config({
|
||||
cloud_name: process.env.NEXT_PUBLIC_CLOUDINARY_CLOUD_NAME,
|
||||
api_key: process.env.NEXT_PUBLIC_CLOUDINARY_API_KEY,
|
||||
api_secret: process.env.NEXT_PUBLIC_CLOUDINARY_API_SECRET,
|
||||
api_key: process.env.CLOUDINARY_API_KEY,
|
||||
api_secret: process.env.CLOUDINARY_API_SECRET,
|
||||
secure: true,
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user