<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Key Management on Lynx Tech Blog</title><link>https://blog.lynxflow.co/en/tags/key-management/</link><description>Recent content in Key Management on Lynx Tech Blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Wed, 02 Sep 2026 01:00:00 +0800</lastBuildDate><atom:link href="https://blog.lynxflow.co/en/tags/key-management/index.xml" rel="self" type="application/rss+xml"/><item><title>What the Server Knows, the Browser Shouldn't Get: Mapping the Frontend Secret-Leakage Surface</title><link>https://blog.lynxflow.co/en/posts/frontend-secret-leakage-ai-era/</link><pubDate>Wed, 02 Sep 2026 01:00:00 +0800</pubDate><guid>https://blog.lynxflow.co/en/posts/frontend-secret-leakage-ai-era/</guid><description>&lt;img src="https://blog.lynxflow.co/images/frontend-secret-leakage-ai-era.png" alt="Featured image of post What the Server Knows, the Browser Shouldn't Get: Mapping the Frontend Secret-Leakage Surface" /&gt;Let’s start with a scenario. You’re building a SaaS product: the backend is connected to a cloud database, the frontend is Next.js, and iteration is moving fast. Before launch, you ask the security team to run a black-box test. On the third day, the report comes back with two high-severity findings:
C1: On the homepage, “View Source” reveals that the JSON inside __NEXT_DATA__ contains the full backend configuration that should have existed only on the server side—database address, message queue</description></item></channel></rss>