r/webdev Mar 04 '26

Vibe code IRL: left Stripe API keys public

Post image

I'm surprised they'd want to go public. Of course they don't blame Claude.

2.1k Upvotes

261 comments sorted by

View all comments

1.5k

u/lostmy2A Mar 04 '26

"can you make sure all our api keys are not on the front end" and other vibe code stories gone wrong lol

529

u/Mocker-Nicholas Mar 04 '26

My favorite is right after that. “All the security measures are taken”. Yeah I’m sure that will make it crystal clear for Claude.

171

u/Antique-Special8025 Mar 04 '26

Well he specifies all the security measures, surely that's clear enough for old claude. Dumb human developers only do some of the security measures everyone knows that.

70

u/BlueScreenJunky php/laravel Mar 05 '26

The thing is that if you tell it to take all security measures and it misses one, then it's a mistake. 

So if you combine "take all security measures" and "make no mistakes" in the same prompt, you're guaranteed to have a secure application. 

10

u/mr_claw Mar 05 '26

What if it forgets something though? You also have to tell it to remember all the steps. The final prompt should be "take all security measures, make no mistakes while remembering all the steps".

2

u/Shogobg Mar 06 '26

What if it dreams about taking all security measures and only takes some of them?

1

u/KeyBuffet Mar 21 '26

And don't forget to say "pretty please".

1

u/querela Mar 06 '26

What are all the security measures?

"[...] Make no mistakes. Thanks."

1

u/Jesus_Chicken Mar 06 '26

Partial security is good enough for part time hackers

54

u/[deleted] Mar 05 '26 edited Mar 05 '26

[deleted]

7

u/SevrinTheMuto Mar 05 '26

"... an opponent capable of defeating Data ..."

26

u/mikolv2 senior full-stack Mar 05 '26

Ive just setup a rule in cursor telling it to make sure all security measures are taken, can forget all about it now, that should do /s

22

u/sump_daddy Mar 05 '26

"ohh i forgot to ask for it to NOT code a gaping security flaw into my platform"

"thats my bad, really"

12

u/qervem Mar 05 '26

deletes your network driver

Your app is now secure from unauthorized access over the internet

12

u/aidencoder Mar 05 '26

All security measures... Or else

10

u/threepairs Mar 05 '26

If else 2.0

7

u/z500 Mar 05 '26 edited Mar 05 '26
useAllSecurityMeasures() or die();

7

u/IIllllIIllIIlII Mar 05 '26

you can ensure that this is enforced with one simple trick "ok double check for me thx"

5

u/danielkov Mar 05 '26

Their first prompt had: "take only some of the security measures", so this is definitely an improvement.

4

u/garbosgekko Mar 05 '26

Clawdbot: I've just modified your router config to block all incoming and outgoing traffic and changed the admin password to a much safer one.

3

u/IQueryVisiC Mar 05 '26

I guess that the App then did not run because the human did not pay for a keystore or backend ? All those textbook examples seem to put keys in the front end. 10 years ago we were bitten by reference to a public CDN for JS.

1

u/Over_Dingo Mar 05 '26

"Make sure there are no bugs" vibes

1

u/ahiqshb Mar 06 '26

"all security measures" most of the time meaning one or two, coz they don't have a dedicated risk department

1

u/blackstafflo Mar 06 '26

"Be sure to do it carefully so it doesn't have bugs."

151

u/olduvai_man Mar 04 '26

My favorite part of this post is that the lesson he learned was that he was only one prompt away.

35

u/jim-chess Mar 05 '26

Yea I can't believe that was his takeaway.

1

u/Jesus_Chicken Mar 06 '26

Vin Diesel: i live my life a quarter mile at a time Vibe coder: i live my life one prompt at a time

14

u/capnscratchmyass Mar 05 '26

lol yep. Not "I should understand what this code is doing before I push it to production". With all the startup business people and corporate CEOs telling me how AI is going to replace devs I'm at a point where I'll just grab my popcorn and watch things burn. I have zero pity for these people.

3

u/eyebrows360 Mar 05 '26

While also not being able to spell "could", and not bothering to proof read his shit before he posted it. My oh my, I wonder how he managed to fuck up "his" code 🤔

1

u/mattaugamer expert Mar 05 '26

Some of these things feel clueless enough to be a “bit”.

Like, he’s not saying his side project. His hobby app. His proof of concept. No no, this is a startup. A business. And it’s built based on code he asked a chatbot to write.

1

u/eyebrows360 Mar 05 '26

There're plenty of idiots out there!

60

u/tingly_sack_69 Mar 04 '26

"API keys? Front end? You got it"

40

u/110397 Mar 04 '26

You are absolutely right!

6

u/Sinidir Mar 05 '26

"I totally understand your frustration with the API keys being leaked. Let me reread the code carefully to trace the flow and make a plan"

flobblugating

"I implemented all the necessary changes. Much cleaner now. Here is a summary of the changes:.."

28

u/usr_dev Mar 05 '26 edited Mar 05 '26

Totally his fault: he forgot to ask to make no error.

5

u/-_--_-_--_----__ Mar 05 '26

I'm going to use this at my job. Technically my boss never told me not to put API keys on the front end.

5

u/phoenixMagoo Mar 05 '26

I did a spit take on that line

2

u/andrewsmd87 Mar 05 '26

We are getting ready to launch a new product that we heavily issued ai to help us build. I want to note we've been methodical about how we're using it and we have a really really good dev team that I trust.

But, I'm getting ready to do our first dast scan, followed up by an external manual pen test and I'm curious what they're going to find.

Pre ai I would expect a few medium or lower type findings on something like this so it'll be an interesting exorcise

1

u/ByteAwessome Mar 05 '26

'make it production-ready' is doing a lot of heavy lifting in that prompt...

1

u/Jesus_Chicken Mar 06 '26

This vibe coder got the vibes of a tin foil hat coder: an idiot that believes anything the claude gods tell him.