nextjs-starter-medusa icon indicating copy to clipboard operation
nextjs-starter-medusa copied to clipboard

NEXT_PUBLIC_MEDUSA_BACKEND_URL- Why would we expose our backend url to the client?

Open sschweimler opened this issue 7 months ago • 1 comments

Is there a specific reason why the backend url in .env.template is exposed to the client by using NEXT_PUBLIC? I think it's a bad idea because it makes the backend visible for potential attackers. If we need to access backend data on the client side, then we should use route handlers or server actions.

sschweimler avatar Jul 10 '24 10:07 sschweimler