# Sourcemap sensitive files leaked

**URL:** https://meta.discourse.org/t/sourcemap-sensitive-files-leaked/259900
**Category:** Support
**Created:** [March 29, 2023, 7:23pm UTC](https://meta.discourse.org/t/sourcemap-sensitive-files-leaked/259900 "2023-03-29T19:23:58Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Rob\_Tsai](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rob_tsai/32/300375_2.png) [@Rob\_Tsai](https://meta.discourse.org/u/Rob_Tsai)
#### Post date: [March 29, 2023, 7:23pm UTC](https://meta.discourse.org/t/sourcemap-sensitive-files-leaked/259900/1 "2023-03-29T19:23:59Z")

</div>

Hi we got a HackenProof bounty about our Discourse site. We have upgrade to v3.10.beta3 +155 but didn’t see anything relevant in the release notes that is relevant to the bounty reported to us. Is this something new or not of concern?

> ### Impact
> 
> The danger is that the attacker obtains the source code and sensitive information , and non-public api
> 
> ### Recommendation
> 
> The temporary solution is to delete the .map file in the code directory; The permanent solution is to disable the function of generating map files during build
> 
> I think you can refer to this link [https://docs.fluidattacks.com/criteria/vulnerabilities/236/](https://docs.fluidattacks.com/criteria/vulnerabilities/236/)

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [March 29, 2023, 7:40pm UTC](https://meta.discourse.org/t/sourcemap-sensitive-files-leaked/259900/2 "2023-03-29T19:40:08Z")

</div>

> [@Rob\_Tsai](#):
>
> Impact： The danger is that the attacker obtains the source code and sensitive information , and non-public api

I think the answer is that there is no non-public API. It’s documented at [GitHub - discourse/discourse: A platform for community discussion. Free, open, simple. · GitHub](https://github.com/discourse/discourse) and if you don’t know how to read that, you can always [Reverse engineer the Discourse API](https://meta.discourse.org/t/reverse-engineer-the-discourse-api/20576).

I really hate bogus security spam.

---

<div class="post-metadata">

### Author: ![MikeNolan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mikenolan/32/297597_2.png) [@MikeNolan](https://meta.discourse.org/u/MikeNolan)
#### Post date: [March 29, 2023, 7:55pm UTC](https://meta.discourse.org/t/sourcemap-sensitive-files-leaked/259900/3 "2023-03-29T19:55:30Z")

</div>

I’m not sure they’re all bogus, but more than a few of them seem like they’re trolling for consulting projects. (But Big Eight accounting firms do that, too, and what they’re usually selling you is a pre-paid report which they revise slightly and charge you $20K.)

---

<div class="post-metadata">

### Author: ![Rob\_Tsai](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rob_tsai/32/300375_2.png) [@Rob\_Tsai](https://meta.discourse.org/u/Rob_Tsai)
#### Post date: [March 29, 2023, 8:08pm UTC](https://meta.discourse.org/t/sourcemap-sensitive-files-leaked/259900/4 "2023-03-29T20:08:53Z")

</div>

Thanks for your feedback. I wasn’t sure if this is truly is an issue.

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [March 29, 2023, 8:15pm UTC](https://meta.discourse.org/t/sourcemap-sensitive-files-leaked/259900/5 "2023-03-29T20:15:52Z")

</div>

> [@MikeNolan](#):
>
> but more than a few of them seem like they’re trolling for consulting projects.

Imagine fishing for a consulting project on the basis of warning someone their source code has leaked … and the site is built on one of the most famous open source projects in existence 😅

---

<div class="post-metadata">

### Author: ![MikeNolan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mikenolan/32/297597_2.png) [@MikeNolan](https://meta.discourse.org/u/MikeNolan)
#### Post date: [March 29, 2023, 8:32pm UTC](https://meta.discourse.org/t/sourcemap-sensitive-files-leaked/259900/6 "2023-03-29T20:32:27Z")

</div>

Yeah, but every time one of these things arrives, I get an email from the executive director asking if this is something to worry about, even though I’m officially retired.
