Living Document Notice
Published 2026-09-13. The evolving architecture, revisions, and connected notes for this dispatch live in the Stax Digital Garden.

Credential Quarantine at the Edge

Credential Quarantine at the Edge: Nocturnal deep violet and spectral green dual-trace CRT macro showing hexagonal quarantine containment ring releasing sanitized vector streamlines

Summary

Single-page web applications that query external commercial telemetry APIs face a recurring architectural flaw: embedding upstream access credentials in client-accessible bundles. When API keys for third-party ADS-B providers or RapidAPI aggregators leak into browser source maps, network tabs, or client memory, they become vulnerable to automated scraping, account exhaustion, and unauthorized billing spikes.

Hushwire implements strict credential quarantine at the edge network boundary, maintaining agentic sandbox boundaries. The browser client never receives, handles, or references upstream authentication tokens. Instead, client applications interact exclusively with a hardened same-origin endpoint (/api/telemetry) powered by Cloudflare Workers. The worker isolates secrets in encrypted runtime environment bindings, validates coordinate bounds to prevent open proxy exploitation, and enforces geographic rate limits. This dispatch covers the secret quarantine topology, defensive parameter validation, and rate-limiting patterns that secure the feed.

The Threat Vectors of Client-Side API Keys

Commercial ADS-B data endpoints charge per query tier or restrict monthly request quotas. Embedding upstream credentials within client-side JavaScript exposes providers to several attack vectors:

[ Compromised Browser Client ]
       │
       ├── Inspects DevTools Network Tab / Memory ──► Exfiltrates Upstream API Token
       │                                                      │
       └── Bypasses Geographic Limits                         ▼
                                                    Direct Unchecked Requests
                                                    to RapidAPI / Data Vendor
                                                              │
                                                    Quota Exhaustion / High Billing
  1. Token Extraction via DevTools: Even minified and obfuscated code easily yields plaintext HTTP request headers via the browser Network inspector.
  2. Malicious Browser Extensions: Content scripts running with elevated permissions can intercept outgoing fetch() headers and exfiltrate credentials to third-party command-and-control servers.
  3. Open Proxy and SSRF Vulnerabilities: Poorly designed edge proxies that accept arbitrary upstream URLs allow attackers to turn the proxy into an open relay, making requests to internal infrastructure or unrelated paid APIs on the operator’s bill.
  4. Billing Denial-of-Service: Once an API key is harvested, automated scripts can cycle requests at high concurrency, exhausting tier allocations in minutes and taking down the legitimate service.

The Edge Quarantine Boundary

To eliminate client exposure, Hushwire separates the network topology into three distinct zones: the Untrusted Browser Zone, the Edge Quarantine Zone, and the Protected Upstream Zone.

┌─────────────────────────┐
│ Untrusted Browser Zone  │
│                         │
│ • hushwire.app          │
│ • Zero API credentials  │
│ • Same-origin requests  │
└────────────┬────────────┘
             │ GET /api/telemetry?lat=37.7&lon=-122.4&rad=50
             ▼
┌────────────────────────────────────────────────────────┐
│ Edge Quarantine Zone (Cloudflare Worker)               │
│                                                        │
│ • Origin & Referer Verification                        │
│ • Coordinate Bounding & Radius Clamp (Max 100 NM)       │
│ • Rate Limiting (IP Token Bucket)                      │
│ • Secret Ingestion via Encrypted Environment Bindings  │
└────────────┬───────────────────────────────────────────┘
             │ GET https://upstream.rapidapi.com/...
             │ Headers: X-RapidAPI-Key: [ENCRYPTED_SECRET]
             ▼
┌─────────────────────────┐
│ Protected Upstream Zone │
│                         │
│ • Commercial Aggregator │
│ • Private VPC / Vendor  │
└─────────────────────────┘

The client communicates solely with /api/telemetry. The upstream endpoint hostname, URL structure, and access credentials remain entirely opaque to the public internet.

Hardened Edge Worker Implementation

The edge proxy enforces multiple defensive layers before forwarding requests to the paid data vendor:

export default {
  async fetch(request, env, ctx) {
    // 1. Enforce strict HTTP method filtering
    if (request.method !== "GET") {
      return new Response("Method Not Allowed", { status: 405 });
    }
 
    // 2. Validate Origin and Sec-Fetch-Site to prevent cross-site hotlinking
    const origin = request.headers.get("Origin");
    const secFetchSite = request.headers.get("Sec-Fetch-Site");
    const allowedHosts = ["hushwire.app", "hushwire-blog.bosunpkm.com", "localhost:3000"];
 
    if (secFetchSite && secFetchSite === "cross-site") {
      return new Response(JSON.stringify({ error: "Unauthorized cross-origin request" }), {
        status: 403,
        headers: { "Content-Type": "application/json" }
      });
    }
 
    // 3. Coordinate parsing with strict geometric clamping
    const url = new URL(request.url);
    const lat = parseFloat(url.searchParams.get("lat"));
    const lon = parseFloat(url.searchParams.get("lon"));
    const rad = parseInt(url.searchParams.get("rad") || "50", 10);
 
    if (isNaN(lat) || isNaN(lon) || lat < -90 || lat > 90 || lon < -180 || lon > 180) {
      return new Response(JSON.stringify({ error: "Invalid coordinate boundaries" }), {
        status: 400,
        headers: { "Content-Type": "application/json" }
      });
    }
 
    // Hard clamp radius to 100 Nautical Miles maximum
    const clampedRadius = Math.max(10, Math.min(rad, 100));
 
    // 4. Client-IP Rate Limiting (1 request per 3 seconds per IP)
    const clientIp = request.headers.get("CF-Connecting-IP") || "0.0.0.0";
    const rateLimitKey = `rate:${clientIp}`;
    const isLimited = await checkRateLimit(rateLimitKey, env.TELEMETRY_KV);
 
    if (isLimited) {
      return new Response(JSON.stringify({ error: "Rate limit exceeded. Poll interval is 4s." }), {
        status: 429,
        headers: {
          "Content-Type": "application/json",
          "Retry-After": "4"
        }
      });
    }
 
    // 5. Construct upstream call using quarantined secrets
    const upstreamUrl = `https://${env.RAPIDAPI_HOST}/v2/lat/${lat.toFixed(4)}/lon/${lon.toFixed(4)}/dist/${clampedRadius}`;
 
    try {
      const upstreamResponse = await fetch(upstreamUrl, {
        method: "GET",
        headers: {
          "X-RapidAPI-Key": env.RAPIDAPI_KEY,      // Injected via wrangler secret
          "X-RapidAPI-Host": env.RAPIDAPI_HOST,
          "Accept": "application/json",
          "User-Agent": "Hushwire-Edge-Proxy/1.0"
        },
        cf: {
          cacheTtl: 3,
          cacheEverything: true
        }
      });
 
      if (!upstreamResponse.ok) {
        return new Response(JSON.stringify({ error: "Upstream gateway error", code: upstreamResponse.status }), {
          status: 502,
          headers: { "Content-Type": "application/json" }
        });
      }
 
      const payload = await upstreamResponse.json();
      return new Response(JSON.stringify(payload), {
        status: 200,
        headers: {
          "Content-Type": "application/json",
          "Cache-Control": "public, max-age=3, stale-while-revalidate=2"
        }
      });
    } catch (err) {
      return new Response(JSON.stringify({ error: "Network transport failure" }), {
        status: 504,
        headers: { "Content-Type": "application/json" }
      });
    }
  }
};
 
async function checkRateLimit(key, kv) {
  if (!kv) return false; // Fail open if KV is unconfigured in dev
  const current = await kv.get(key);
  if (current) {
    return true; // Key exists, request made too recently
  }
  // Store key with 3-second TTL
  await kv.put(key, "1", { expirationTtl: 60 });
  return false;
}

Secret Management and Deployment

Secrets are provisioned into the Cloudflare Worker runtime through encrypted CLI bindings during deployment, never committed to Git repositories or written to disk:

# Provisioning the upstream API token securely
wrangler secret put RAPIDAPI_KEY
# [Enter sensitive token string when prompted]
 
# Provisioning host configuration
wrangler secret put RAPIDAPI_HOST
# Value: adsb-exchange.p.rapidapi.com

In production, environment variables reside in memory within isolated V8 micro-containers. They cannot be extracted via JavaScript inspection from the outside, and any worker failure logs sanitize outbound request headers to prevent leakage in telemetry aggregators.

Security Posture Verification

Attack VectorVulnerable Direct ArchitectureQuarantined Edge Architecture
API Key DiscoveryInstant via Browser DevTools Network tabZero token visibility; headers stripped at edge
Arbitrary Upstream CallsAttacker can call any paid vendor endpointProxy URL is fixed; only lat/lon parameters accepted
Geographic AbuseAttacker scans entire continents concurrentlyRadius clamped to 100 NM; rate-limited per IP
Hotlinking / LeechingOther sites can embed client and consume keySec-Fetch-Site and Origin verification reject hotlinking

By moving credential ownership completely to the edge, Hushwire protects operational budgets while keeping the client application simple, portable, and secure.


  • Directus Target: hushwire
  • Garden Source Reference: Edge Secrets Management, Worker Security Posture, MOC - Fleet Operations, MOC - Bosun PKM Tools, MOC - Agentic Containment and Sandbox Boundaries