# Is publishing to a web app safe?

**URL:** <https://community.thunkable.com/t/is-publishing-to-a-web-app-safe/1388370>\
**Category:** Questions about Thunkable X\
**Created:** [July 10, 2021, 5:28am UTC](https://community.thunkable.com/t/is-publishing-to-a-web-app-safe/1388370 "2021-07-10T05:28:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![samclever](https://avatars.discourse-cdn.com/v4/letter/s/ec9cab/32.png) [@samclever](https://community.thunkable.com/u/samclever)\
**Post date:** [July 10, 2021, 5:28am UTC](https://community.thunkable.com/t/is-publishing-to-a-web-app-safe/1388370/1 "2021-07-10T05:28:38Z")

</div>

I am curious, if I publish my app as a responsive web app, can someone use webpage developer tools to view the apps code/data? I am making a dispatching app for my job and need it to be secure. I’m just curious what sort of “security” our apps really have.

---

<div class="post-metadata">

**Author:** ![catsarisky](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/catsarisky/32/100661_2.png) [@catsarisky](https://community.thunkable.com/u/catsarisky)\
**Post date:** [July 10, 2021, 1:33pm UTC](https://community.thunkable.com/t/is-publishing-to-a-web-app-safe/1388370/2 "2021-07-10T13:33:51Z")

</div>

What specifically are you trying to protect? The code itself, or API keys/secrets within the code?

---

<div class="post-metadata">

**Author:** ![samclever](https://avatars.discourse-cdn.com/v4/letter/s/ec9cab/32.png) [@samclever](https://community.thunkable.com/u/samclever)\
**Post date:** [July 13, 2021, 9:18pm UTC](https://community.thunkable.com/t/is-publishing-to-a-web-app-safe/1388370/3 "2021-07-13T21:18:35Z")

</div>

Both I suppose, though the code itself isnt as big and issue.

---

<div class="post-metadata">

**Author:** ![catsarisky](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/catsarisky/32/100661_2.png) [@catsarisky](https://community.thunkable.com/u/catsarisky)\
**Post date:** [July 13, 2021, 11:03pm UTC](https://community.thunkable.com/t/is-publishing-to-a-web-app-safe/1388370/4 "2021-07-13T23:03:17Z")

</div>

Rule #1 - don’t take internet security advice from unvetted random strangers.

With that said…

Only a member of the Thunkable staff can really tell you about what level of encryption/obfuscation they’re using.

But YOU have the ability to control what data the app has. If you require the user to authenticate with Firebase, and then you write wise Firebase rules that restrict what data that authenticated user can access, you’ll have taken a pretty good step towards only letting the user access their own data. Think carefully about what bins your data go into and which bins each user can read and write. Don’t give a user more permissions than they need to have, even if you don’t provide the ability to change something in the app, don’t provide it period.

If you have sensitive data, your app should /not/ slurp all of it and then decide what parts the user is allowed to see.

This is likely a good place to start: [Firebase Security Rules](https://firebase.google.com/docs/rules)

---

<div class="post-metadata">

**Author:** ![ioannis](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/ioannis/32/146956_2.png) [@ioannis](https://community.thunkable.com/u/ioannis)\
**Post date:** [November 8, 2024, 1:19pm UTC](https://community.thunkable.com/t/is-publishing-to-a-web-app-safe/1388370/5 "2024-11-08T13:19:50Z")

</div>


