My static site was serving my internal engineering handoff doc to anyone

My static site was serving my internal docs

A static host published the repo root as the build output, so every committed file — including a 150 KB handoff doc with an admin bypass parameter and a schema hole — was a public URL. Two CDN purges silently failed because the stale copy lived in a different cache layer. The real fix was a server-side schema change, not rotating the exposed value, which had always been visible in view-source.

The leaked document was never the exposure — view-source was, and it always would be, for whatever value I put there.

More from this day

2026-10-10