A client-side key with no origin restrictions — documented with the minimum necessary proof.
| Target | wing.com/get-delivery |
|---|---|
| Source | client-side bundle (zone.js) |
| Key | AIzaSy…[REDACTED] — masked; reported to Google VRP |
| API surface | Google Maps (JS / Geocoding / Street View) |
| Restrictions | None observed (usable from any origin) |
| Class | Exposed credential / missing key restriction (CWE-200, CWE-284) |
One successful Geocoding request from an unrelated origin confirms the key is not referrer-restricted:
A valid 200 OK is sufficient. No looping or volume testing is required or appropriate.
An unrestricted, billable key can be reused from any origin, so a third party's usage is billed to the key owner and can consume its quota. It does not bypass authentication or expose user data. Impact is bounded by whether the key is enabled/billed and by Google's per-key quotas and abuse protections.
wing.com).