Living Document Notice
Published 2026-09-13. The evolving architecture, revisions, and connected notes for this dispatch live in the Stax Digital Garden.
Credential Quarantine at the Edge
Summary
Single-page web applications that query external commercial telemetry APIs face a recurring architectural flaw: embedding upstream access credentials in client-accessible bundles. When API keys for third-party ADS-B providers or RapidAPI aggregators leak into browser source maps, network tabs, or client memory, they become vulnerable to automated scraping, account exhaustion, and unauthorized billing spikes.
Hushwire implements strict credential quarantine at the edge network boundary, maintaining agentic sandbox boundaries. The browser client never receives, handles, or references upstream authentication tokens. Instead, client applications interact exclusively with a hardened same-origin endpoint (/api/telemetry) powered by Cloudflare Workers. The worker isolates secrets in encrypted runtime environment bindings, validates coordinate bounds to prevent open proxy exploitation, and enforces geographic rate limits. This dispatch covers the secret quarantine topology, defensive parameter validation, and rate-limiting patterns that secure the feed.
The Threat Vectors of Client-Side API Keys
Commercial ADS-B data endpoints charge per query tier or restrict monthly request quotas. Embedding upstream credentials within client-side JavaScript exposes providers to several attack vectors:
[ Compromised Browser Client ]
│
├── Inspects DevTools Network Tab / Memory ──► Exfiltrates Upstream API Token
│ │
└── Bypasses Geographic Limits ▼
Direct Unchecked Requests
to RapidAPI / Data Vendor
│
Quota Exhaustion / High Billing
- Token Extraction via DevTools: Even minified and obfuscated code easily yields plaintext HTTP request headers via the browser Network inspector.
- Malicious Browser Extensions: Content scripts running with elevated permissions can intercept outgoing
fetch()headers and exfiltrate credentials to third-party command-and-control servers. - Open Proxy and SSRF Vulnerabilities: Poorly designed edge proxies that accept arbitrary upstream URLs allow attackers to turn the proxy into an open relay, making requests to internal infrastructure or unrelated paid APIs on the operator’s bill.
- Billing Denial-of-Service: Once an API key is harvested, automated scripts can cycle requests at high concurrency, exhausting tier allocations in minutes and taking down the legitimate service.
The Edge Quarantine Boundary
To eliminate client exposure, Hushwire separates the network topology into three distinct zones: the Untrusted Browser Zone, the Edge Quarantine Zone, and the Protected Upstream Zone.
┌─────────────────────────┐
│ Untrusted Browser Zone │
│ │
│ • hushwire.app │
│ • Zero API credentials │
│ • Same-origin requests │
└────────────┬────────────┘
│ GET /api/telemetry?lat=37.7&lon=-122.4&rad=50
▼
┌────────────────────────────────────────────────────────┐
│ Edge Quarantine Zone (Cloudflare Worker) │
│ │
│ • Origin & Referer Verification │
│ • Coordinate Bounding & Radius Clamp (Max 100 NM) │
│ • Rate Limiting (IP Token Bucket) │
│ • Secret Ingestion via Encrypted Environment Bindings │
└────────────┬───────────────────────────────────────────┘
│ GET https://upstream.rapidapi.com/...
│ Headers: X-RapidAPI-Key: [ENCRYPTED_SECRET]
▼
┌─────────────────────────┐
│ Protected Upstream Zone │
│ │
│ • Commercial Aggregator │
│ • Private VPC / Vendor │
└─────────────────────────┘
The client communicates solely with /api/telemetry. The upstream endpoint hostname, URL structure, and access credentials remain entirely opaque to the public internet.
Hardened Edge Worker Implementation
The edge proxy enforces multiple defensive layers before forwarding requests to the paid data vendor:
export default {
async fetch(request, env, ctx) {
// 1. Enforce strict HTTP method filtering
if (request.method !== "GET") {
return new Response("Method Not Allowed", { status: 405 });
}
// 2. Validate Origin and Sec-Fetch-Site to prevent cross-site hotlinking
const origin = request.headers.get("Origin");
const secFetchSite = request.headers.get("Sec-Fetch-Site");
const allowedHosts = ["hushwire.app", "hushwire-blog.bosunpkm.com", "localhost:3000"];
if (secFetchSite && secFetchSite === "cross-site") {
return new Response(JSON.stringify({ error: "Unauthorized cross-origin request" }), {
status: 403,
headers: { "Content-Type": "application/json" }
});
}
// 3. Coordinate parsing with strict geometric clamping
const url = new URL(request.url);
const lat = parseFloat(url.searchParams.get("lat"));
const lon = parseFloat(url.searchParams.get("lon"));
const rad = parseInt(url.searchParams.get("rad") || "50", 10);
if (isNaN(lat) || isNaN(lon) || lat < -90 || lat > 90 || lon < -180 || lon > 180) {
return new Response(JSON.stringify({ error: "Invalid coordinate boundaries" }), {
status: 400,
headers: { "Content-Type": "application/json" }
});
}
// Hard clamp radius to 100 Nautical Miles maximum
const clampedRadius = Math.max(10, Math.min(rad, 100));
// 4. Client-IP Rate Limiting (1 request per 3 seconds per IP)
const clientIp = request.headers.get("CF-Connecting-IP") || "0.0.0.0";
const rateLimitKey = `rate:${clientIp}`;
const isLimited = await checkRateLimit(rateLimitKey, env.TELEMETRY_KV);
if (isLimited) {
return new Response(JSON.stringify({ error: "Rate limit exceeded. Poll interval is 4s." }), {
status: 429,
headers: {
"Content-Type": "application/json",
"Retry-After": "4"
}
});
}
// 5. Construct upstream call using quarantined secrets
const upstreamUrl = `https://${env.RAPIDAPI_HOST}/v2/lat/${lat.toFixed(4)}/lon/${lon.toFixed(4)}/dist/${clampedRadius}`;
try {
const upstreamResponse = await fetch(upstreamUrl, {
method: "GET",
headers: {
"X-RapidAPI-Key": env.RAPIDAPI_KEY, // Injected via wrangler secret
"X-RapidAPI-Host": env.RAPIDAPI_HOST,
"Accept": "application/json",
"User-Agent": "Hushwire-Edge-Proxy/1.0"
},
cf: {
cacheTtl: 3,
cacheEverything: true
}
});
if (!upstreamResponse.ok) {
return new Response(JSON.stringify({ error: "Upstream gateway error", code: upstreamResponse.status }), {
status: 502,
headers: { "Content-Type": "application/json" }
});
}
const payload = await upstreamResponse.json();
return new Response(JSON.stringify(payload), {
status: 200,
headers: {
"Content-Type": "application/json",
"Cache-Control": "public, max-age=3, stale-while-revalidate=2"
}
});
} catch (err) {
return new Response(JSON.stringify({ error: "Network transport failure" }), {
status: 504,
headers: { "Content-Type": "application/json" }
});
}
}
};
async function checkRateLimit(key, kv) {
if (!kv) return false; // Fail open if KV is unconfigured in dev
const current = await kv.get(key);
if (current) {
return true; // Key exists, request made too recently
}
// Store key with 3-second TTL
await kv.put(key, "1", { expirationTtl: 60 });
return false;
}Secret Management and Deployment
Secrets are provisioned into the Cloudflare Worker runtime through encrypted CLI bindings during deployment, never committed to Git repositories or written to disk:
# Provisioning the upstream API token securely
wrangler secret put RAPIDAPI_KEY
# [Enter sensitive token string when prompted]
# Provisioning host configuration
wrangler secret put RAPIDAPI_HOST
# Value: adsb-exchange.p.rapidapi.comIn production, environment variables reside in memory within isolated V8 micro-containers. They cannot be extracted via JavaScript inspection from the outside, and any worker failure logs sanitize outbound request headers to prevent leakage in telemetry aggregators.
Security Posture Verification
| Attack Vector | Vulnerable Direct Architecture | Quarantined Edge Architecture |
|---|---|---|
| API Key Discovery | Instant via Browser DevTools Network tab | Zero token visibility; headers stripped at edge |
| Arbitrary Upstream Calls | Attacker can call any paid vendor endpoint | Proxy URL is fixed; only lat/lon parameters accepted |
| Geographic Abuse | Attacker scans entire continents concurrently | Radius clamped to 100 NM; rate-limited per IP |
| Hotlinking / Leeching | Other sites can embed client and consume key | Sec-Fetch-Site and Origin verification reject hotlinking |
By moving credential ownership completely to the edge, Hushwire protects operational budgets while keeping the client application simple, portable, and secure.
- Directus Target: hushwire
- Garden Source Reference: Edge Secrets Management, Worker Security Posture, MOC - Fleet Operations, MOC - Bosun PKM Tools, MOC - Agentic Containment and Sandbox Boundaries