# Sensitve information in variables and auth cookie

**URL:** <https://community.weweb.io/t/sensitve-information-in-variables-and-auth-cookie/19350>\
**Category:** How do I?\
**Created:** [July 23, 2025, 2:17am UTC](https://community.weweb.io/t/sensitve-information-in-variables-and-auth-cookie/19350 "2025-07-23T02:17:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![JulianW](https://avatars.discourse-cdn.com/v4/letter/j/85e7bf/32.png) [@JulianW](https://community.weweb.io/u/JulianW)\
**Post date:** [July 23, 2025, 2:17am UTC](https://community.weweb.io/t/sensitve-information-in-variables-and-auth-cookie/19350/1 "2025-07-23T02:17:53Z")

</div>

It seems like everything that is in variables as well as whatever is used for the OIDC connection is available in the browser and can be seen and exposed in the browser.  
How do you use weweb and especially variables that include sensitive data (tokens or even just group member for RBAC) in a secure manner? Right now it seems like it’s pretty much an open door from a security perspective

---

<div class="post-metadata">

**Author:** ![sam1](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/sam1/32/6724_2.png) [@sam1](https://community.weweb.io/u/sam1)\
**Post date:** [July 23, 2025, 2:37am UTC](https://community.weweb.io/t/sensitve-information-in-variables-and-auth-cookie/19350/2 "2025-07-23T02:37:42Z")

</div>

variables are exposed its normal for web development this post explains more. If you have something that needs to be secret use backend functions and supabase secrets for example to do that.

> [@Variables are safe?](https://community.weweb.io/t/variables-are-safe/7717):
>
> Can a malicious user manipulate my application’s variables and display, for example, a modal with conditional rendering based on a variable?

There’s a bunch of other posts around that go into more detail on security as well. Pretty sure weweb has a video on it themselves actually

---

<div class="post-metadata">

**Author:** ![JulianW](https://avatars.discourse-cdn.com/v4/letter/j/85e7bf/32.png) [@JulianW](https://community.weweb.io/u/JulianW)\
**Post date:** [July 23, 2025, 2:47am UTC](https://community.weweb.io/t/sensitve-information-in-variables-and-auth-cookie/19350/3 "2025-07-23T02:47:26Z")

</div>

The biggest problem is the OIDC plugin, since it’s relying on the auth cookie, which you can easily manipulate. So all the RBAC provided by weweb goes down the drain.  
If it would be immutable, it would fix the issue, but this also doesn’t seem to be the case

---

<div class="post-metadata">

**Author:** ![sam1](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/sam1/32/6724_2.png) [@sam1](https://community.weweb.io/u/sam1)\
**Post date:** [July 23, 2025, 5:57am UTC](https://community.weweb.io/t/sensitve-information-in-variables-and-auth-cookie/19350/4 "2025-07-23T05:57:44Z")

</div>

If you change anything in the jwt ie the cookie when you go to fetch from your database it will fail because the JWT signature is wrong.
