# Sensitve information in variables and auth cookie

**URL:** <https://community.weweb.io/t/sensitve-information-in-variables-and-auth-cookie/19350>\
**Category:** How do I?\
**Created:** [July 23, 2025, 2:17am UTC](https://community.weweb.io/t/sensitve-information-in-variables-and-auth-cookie/19350 "2025-07-23T02:17:53Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![sam1](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/sam1/32/6724_2.png) [@sam1](https://community.weweb.io/u/sam1)\
**Post date:** [July 23, 2025, 2:37am UTC](https://community.weweb.io/t/sensitve-information-in-variables-and-auth-cookie/19350/2 "2025-07-23T02:37:42Z")

</div>

variables are exposed its normal for web development this post explains more. If you have something that needs to be secret use backend functions and supabase secrets for example to do that.

> [@Variables are safe?](https://community.weweb.io/t/variables-are-safe/7717):
>
> Can a malicious user manipulate my application’s variables and display, for example, a modal with conditional rendering based on a variable?

There’s a bunch of other posts around that go into more detail on security as well. Pretty sure weweb has a video on it themselves actually

---

_[View the full topic](https://community.weweb.io/t/sensitve-information-in-variables-and-auth-cookie/19350)._
