# Trust the author - the meaning

**URL:** <https://community.glideapps.com/t/trust-the-author-the-meaning/29674>\
**Category:** Ask for Help\
**Tags:** custom-code\
**Created:** [July 28, 2021, 8:30pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674 "2021-07-28T20:30:35Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Krivo](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/krivo/32/5363_2.png) [@Krivo](https://community.glideapps.com/u/Krivo)\
**Post date:** [July 28, 2021, 8:30pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/1 "2021-07-28T20:30:35Z")

</div>

Can somebody elaborate on the meaning of the quotes below.

If the code is actually run on the device well it doesn’t get send to place where the code is hosted - isn’t that correct?

Of course you should be aware of what is in the code so the code doesn’t copy your data to a malicious site - but if you are in control of the code then this shouldn’t be a problem, I expect.

> **Make Sure You Trust The Author** If you’re using code written or hosted by someone else – make sure you trust the author. Experimental Code columns can access any data you pass to them so it’s important you are confident with where it’s going.

> (in reality, the code runs on your device, but it’s useful to think of it this way 👆🏼)

So can you pass a secret key to e.g. Cloudinary exposed API in order to get hold on some data from your account there - without passing the secret key to the place where the code is hosted?

Or will the secret key be accessible on the device that runs the app - e.g. by inspecting the code?

---

<div class="post-metadata">

**Author:** ![david](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/david/32/62831_2.png) [@david](https://community.glideapps.com/u/david)\
**Post date:** [July 28, 2021, 9:51pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/2 "2021-07-28T21:51:31Z")

</div>

The author of the Experimental Code column could, if they wanted to, add some code to send all information you send to it to some server they control, and do whatever they want with it, no matter _where_ the code runs.

Suppose I make an Experimental Code column called “Validate Credit Card Number” and I share it here. While validating, that code column could make purchases with the credit card. It does not matter that the code is running on the device.

The best thing to do is _copy_ and code columns that you want to use, so they are under your exclusive control. Then you can see for yourself exactly what the code does, and nobody can change it but you.

If this feature is popular, we will create some process to help you figure out which code columns are trusted by Glide, and which are not.

---

<div class="post-metadata">

**Author:** ![Krivo](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/krivo/32/5363_2.png) [@Krivo](https://community.glideapps.com/u/Krivo)\
**Post date:** [July 28, 2021, 9:57pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/3 "2021-07-28T21:57:28Z")

</div>

@david thanks. Think I understand. You just got to be in control of the code. Yes.

But when you run the code it is running on the users device - and do not send any data to the origin of the code, right?

---

<div class="post-metadata">

**Author:** ![david](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/david/32/62831_2.png) [@david](https://community.glideapps.com/u/david)\
**Post date:** [July 28, 2021, 9:58pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/4 "2021-07-28T21:58:18Z")

</div>

That’s right, Glide does not send data _to_ where the code column is hosted. It theory, this should even allow code columns to work offline (I haven’t tested that). But, the code could then do whatever it wants.

---

<div class="post-metadata">

**Author:** ![Krivo](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/krivo/32/5363_2.png) [@Krivo](https://community.glideapps.com/u/Krivo)\
**Post date:** [July 28, 2021, 10:07pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/5 "2021-07-28T22:07:34Z")

</div>

@david is there any way where we can use external api which uses api keys/passwords- and not disclose the keys/passwords to the users (who might be inspecting the code). The api info is to be used by everybody of the app.

---

<div class="post-metadata">

**Author:** ![david](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/david/32/62831_2.png) [@david](https://community.glideapps.com/u/david)\
**Post date:** [July 28, 2021, 10:46pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/6 "2021-07-28T22:46:44Z")

</div>

No, there is no safe way to do this yet.

---

<div class="post-metadata">

**Author:** ![gvalero](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/gvalero/32/1037_2.png) [@gvalero](https://community.glideapps.com/u/gvalero)\
**Post date:** [July 28, 2021, 11:13pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/7 "2021-07-28T23:13:21Z")

</div>

What about if we use the Hell Yes-Code?

> **[glide-yes-code-hell-yes](https://replit.com/@MarkProbst/glide-yes-code-hell-yes#function.js)**
>
> A HTML, CSS, JS repl by MarkProbst

In my tests, I prefer to create my code using the Mark’s Yes-Code while it’s posible (it’s multi-use and reusable) instead of creating new code for each purpose/need.

If the API key is sent as parameter (part of code sent as string), isn’t it safer than write and show API Key in Function.js?

Gracias @david

---

<div class="post-metadata">

**Author:** ![gvalero](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/gvalero/32/1037_2.png) [@gvalero](https://community.glideapps.com/u/gvalero)\
**Post date:** [July 29, 2021, 7:33pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/8 "2021-07-29T19:33:30Z")

</div>

Hola @Krivo

Are you able to test and inspect the code to find API key using my idea written above?

The trick is use the _Hell Yes-Code_ otherwise, we have a big security problem.

Thanks!

---

<div class="post-metadata">

**Author:** ![Krivo](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/krivo/32/5363_2.png) [@Krivo](https://community.glideapps.com/u/Krivo)\
**Post date:** [July 29, 2021, 7:48pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/9 "2021-07-29T19:48:04Z")

</div>

@gvalero i’m not a great hacker 😉  
Anyhow, you didn’t supply a link to an app so I cannot try it out. What are you connecting to - to google maps?

---

<div class="post-metadata">

**Author:** ![Mark](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/mark/32/125_2.png) [@Mark](https://community.glideapps.com/u/Mark)\
**Post date:** [July 29, 2021, 7:48pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/10 "2021-07-29T19:48:17Z")

</div>

@gvalero If you pass the API key into the Code column through a parameter, then only people who can access the app can potentially see the API key.

---

<div class="post-metadata">

**Author:** ![Mark](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/mark/32/125_2.png) [@Mark](https://community.glideapps.com/u/Mark)\
**Post date:** [July 29, 2021, 7:49pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/11 "2021-07-29T19:49:43Z")

</div>

If the column code is loaded before going offline, the Code column will work offline as long as it doesn’t require the network.

---

<div class="post-metadata">

**Author:** ![Krivo](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/krivo/32/5363_2.png) [@Krivo](https://community.glideapps.com/u/Krivo)\
**Post date:** [July 29, 2021, 7:51pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/12 "2021-07-29T19:51:02Z")

</div>

@mark so if the user opens the app at a computer then he will be able to inspect the code and find the api key?

---

<div class="post-metadata">

**Author:** ![Mark](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/mark/32/125_2.png) [@Mark](https://community.glideapps.com/u/Mark)\
**Post date:** [July 29, 2021, 7:54pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/13 "2021-07-29T19:54:20Z")

</div>

Yes.

---

<div class="post-metadata">

**Author:** ![Krivo](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/krivo/32/5363_2.png) [@Krivo](https://community.glideapps.com/u/Krivo)\
**Post date:** [July 29, 2021, 7:59pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/14 "2021-07-29T19:59:31Z")

</div>

@mark ok. So no secure way to pass on a api key by use of experimental column. It would be so fantastic to be able to connect to an external api where you need to provide api key/secret. It would open up a lot of new possibilities. Hope you are considering how to do that.

---

<div class="post-metadata">

**Author:** ![Mark](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/mark/32/125_2.png) [@Mark](https://community.glideapps.com/u/Mark)\
**Post date:** [July 29, 2021, 8:00pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/15 "2021-07-29T20:00:54Z")

</div>

There is no secure way to do that when the code runs on the user’s device.

---

<div class="post-metadata">

**Author:** ![Krivo](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/krivo/32/5363_2.png) [@Krivo](https://community.glideapps.com/u/Krivo)\
**Post date:** [July 29, 2021, 8:19pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/16 "2021-07-29T20:19:11Z")

</div>

@mark but Glide can (in the future) create an api column that is secure? Isn’t that correct?

Or we can at the moment use a webhook to e.g. integromat which does the retrieval of data from the 3rd party api - and then integromat could send the data back to glide (through google sheets at the moment). If Glide could retrieve data directly in Glide tables then we would have a fast and secure solution as well.

---

<div class="post-metadata">

**Author:** ![Uzo](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/uzo/32/22639_2.png) [@Uzo](https://community.glideapps.com/u/Uzo)\
**Post date:** [July 29, 2021, 9:55pm UTC](https://community.glideapps.com/t/trust-the-author-the-meaning/29674/17 "2021-07-29T21:55:10Z")

</div>

[https://community.glideapps.com/t/please-help-us-test-yes-code-column/28870/149?u=uzo](https://community.glideapps.com/t/please-help-us-test-yes-code-column/28870/149)

I think the problem is solved!.. until some of Glide’s top experts will hack my [SAMPLE](https://test-sa.glideapp.io/) … LOL  
PM me the API key if you can find it… and I will start working on a new solution.
