DevNet Associate (DEVASC) v1.0Understanding and Using APIsHard
A security auditor is reviewing an application that uses a Cisco API. They discover that the application stores API keys directly in the client-side JavaScript code. What is the primary security risk associated with this practice?
- AIncompatibility with OpenAPI documentation standards.
- BExposure of sensitive API keys to unauthorized users.
- CIncreased API latency due to client-side processing.
- DViolation of RESTful statelessness principles.
Show answer & explanationAnswer & explanation
Correct answer: B. Exposure of sensitive API keys to unauthorized users.
Storing API keys directly in client-side JavaScript code (e.g., in a web browser) makes them easily accessible to anyone who inspects the page source or network traffic. This exposes the sensitive keys, allowing unauthorized users to potentially misuse the API.
Why the other options are wrong
- A. OpenAPI documentation describes API structure, not client-side implementation details or security practices.
- C. Storing keys client-side has no direct impact on API latency; latency is related to network and server performance.
- D. API key storage location is unrelated to RESTful statelessness, which concerns server session management.
Client-side API Key Exposure
Storing API keys directly in client-side code (e.g., JavaScript) is a major security vulnerability as it exposes the keys to public view, allowing unauthorized access and misuse of the API.
- Client-side code is publicly viewable.
- Exposes keys to malicious actors.
- Leads to unauthorized API access.
- API keys should be stored on the server-side or securely transmitted.
Memory trick: Never expose your API key to the client's 'eyes'.