Hi, GrowthBook Team, We’ve identified an issue in...
# ask-questions
a
Hi, GrowthBook Team, We’ve identified an issue in the growthbook-proxy project: the /api/eval/ endpoint includes internal targeting logic via tracks[].result.experiment.condition. This allows downstream clients to infer segmentation criteria, which seems to undermine the Remote Evaluation promise to “hide your features’ business logic in insecure environments.” We’ve opened an issue with full context and a proposal to add an optional sanitization step: https://github.com/growthbook/growthbook-proxy/issues/95
👀 2
h
Thanks for the catch! Proposed fix here if you'd like to follow along: https://github.com/growthbook/growthbook-proxy/pull/96
Hi @alert-engineer-79348, the issue should be patched on the latest remoteEval and proxy releases.
🙌 1