Filtered by tag: #graphql · clear
How a poke around Spur.us's authenticated dashboard led to a full GraphQL schema dump of their billing provider, a free subscription upgrade to Enterprise, and leaked Stripe secrets, all from client-side credentials.