SShortSingh.
Back to feed

HAR Files Can Expose Auth Tokens and Secrets — Here's How to Share Them Safely

0
·1 views

A HAR file, commonly requested by support teams to debug browser issues, can contain sensitive data including session cookies, API keys, authorization headers, and user account details. Security guidance recommends capturing the smallest possible reproduction, using a test account where feasible, and carefully redacting secret values rather than deleting entire objects that may be needed for diagnosis. Analysts should search headers, cookies, query parameters, and response bodies — not just URLs — before sharing any HAR file. A consistent redaction approach, such as replacing repeated identifiers with uniform placeholders, helps preserve diagnostic context without exposing credentials. After sharing, revoking any captured session tokens or rotating API keys is advised as a final safeguard.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingHacker News ·

German battery maker Varta files for insolvency

German battery manufacturer Varta has filed insolvency applications, marking a significant financial setback for the company. Varta is a well-known producer of batteries, including small cells used in consumer electronics and hearing aids. The filing was reported on July 24, 2026, signaling the company's inability to meet its financial obligations. This development raises concerns about the future of the firm and its workforce. The insolvency process will now determine how the company's debts and assets are handled going forward.

0
ProgrammingDEV Community ·

Key AWS S3 and CloudFront Edge Cases for Static Site Subdirectory Hosting

A developer deploying a static documentation site on AWS S3 and CloudFront encountered several non-obvious routing and configuration issues. Browser caching of 301 redirects and HSTS policies caused stale behavior in normal sessions even after infrastructure changes had propagated. CloudFront's Default Root Object only resolves index files at the distribution root, not in subdirectories, requiring explicit URL rewriting via a CloudFront Function on the Viewer Request event. Missing trailing slashes in subdirectory URLs caused browsers to misresolve relative asset paths, breaking CSS and JavaScript loading. A concise CloudFront Function that redirects slash-less directory requests and rewrites directory URIs to index.html was found to resolve most of these routing problems.

0
ProgrammingDEV Community ·

Gemini 3.6 Flash's Thinking Dial Can Cut AI Costs 30x With Accuracy Trade-offs

Google's Gemini 3.6 Flash, which became generally available on July 21, 2026, charges users for hidden 'reasoning tokens' in addition to standard output tokens, billed at $7.50 per million. Independent testing conducted on July 24, 2026, found that the model's reasoning effort setting — ranging from minimal to high — can swing costs by up to 30 times on the same task, dropping a 120-word writing task from $0.03316 to $0.00110. Setting reasoning effort to 'minimal' eliminates reasoning tokens entirely and cuts per-call costs by 91–97%, with no noticeable quality loss on retrieval, formatting, and simple factual tasks. However, the minimal setting caused the model to fail all three attempts at a multi-step arithmetic word problem, highlighting a meaningful accuracy risk for complex reasoning tasks. The model's 1-million-token context window and prompt caching behavior were confirmed to match Google's published specifications in testing.

0
ProgrammingDEV Community ·

Developer Builds CI Enforcement Layer on Top of BenchmarkDotNet for .NET Projects

A developer working on a reconciliation tool called CedarRecon identified a gap in .NET performance testing: BenchmarkDotNet measures performance but does not enforce any budget or threshold policy. While dogfooding an early version of the tool, a 28% regression was detected in an unrelated method — the kind of finding that can be missed when manually reviewing CI logs. To address this, the developer built Cedar.BenchmarkGate, an open-source tool that adds committed baselines, configurable regression thresholds, and pass/fail exit codes to the benchmarking workflow. The tool is designed to run without any SaaS dependency or hosted database, making it suitable as a lightweight CI gate. Version 0.1.0-alpha.1 is now live, with planned documentation covering baseline architecture, policy separation, and the exit-code contract.

HAR Files Can Expose Auth Tokens and Secrets — Here's How to Share Them Safely · ShortSingh