<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/false-security-dashy-s-client-side-authentication-kezge8hak" -->

---
title: False security: Dashy&#x27;s client-side authentication
description: Dashy, a popular dashboard app, has a fundamentally broken client-side authentication system that can be easily bypassed, leaving sensitive information...
canonical: https://daily.dev/posts/false-security-dashy-s-client-side-authentication-kezge8hak
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: False security: Dashy&#x27;s client-side authentication | daily.dev
og:description: Dashy, a popular dashboard app, has a fundamentally broken client-side authentication system that can be easily bypassed, leaving sensitive information...
og:url: https://daily.dev/posts/false-security-dashy-s-client-side-authentication-kezge8hak
og:image: https://api.daily.dev/og/posts/kezGE8haK.png
og:image:alt: False security: Dashy&#x27;s client-side authentication
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# False security: Dashy's client-side authentication

**[Lobsters](https://daily.dev/sources/lobsters)** · 9 min read · 2 upvotes · 0 comments

## Summary

Dashy, a popular dashboard app, has a fundamentally broken client-side authentication system that can be easily bypassed, leaving sensitive information exposed. The app's security depends on the user's browser, making it vulnerable to tampering. Dashy recommends alternative authentication methods like reverse proxies to ensure better security. Dashy's developers are advised to update the project documentation and consider removing the authentication system entirely. Users are cautioned to be careful when storing API keys in widget configurations and to use extra caution when exposing Dashy to the internet.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://subract.dev/posts/dashy/>

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments

---

Tags: [#authentication](https://daily.dev/tags/authentication), [#security](https://daily.dev/tags/security), [#self-hosting](https://daily.dev/tags/self-hosting), [#webdev](https://daily.dev/tags/webdev)

[View this post on daily.dev](https://daily.dev/posts/false-security-dashy-s-client-side-authentication-kezge8hak)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"False security: Dashy's client-side authentication","url":"https://daily.dev/posts/false-security-dashy-s-client-side-authentication-kezge8hak","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/false-security-dashy-s-client-side-authentication-kezge8hak"},"datePublished":"2024-03-29T14:04:35.616Z","dateModified":"2024-05-24T02:15:06.931Z","description":"Dashy, a popular dashboard app, has a fundamentally broken client-side authentication system that can be easily bypassed, leaving sensitive information...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e105c57a37689bb9dc36b78d3da1e3ca?_a=AQAEufR","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e105c57a37689bb9dc36b78d3da1e3ca?_a=AQAEufR","isAccessibleForFree":true,"articleSection":"Lobsters","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Lobsters","logo":"https://media.daily.dev/image/upload/s--tl8v_Fku--/f_auto,t_logo/v1698841318/logos/lobste.jpg","url":"https://daily.dev/sources/lobsters"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/false-security-dashy-s-client-side-authentication-kezge8hak","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"authentication,security,self-hosting,webdev","timeRequired":"PT9M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Lobsters","item":"https://daily.dev/sources/lobsters"},{"@type":"ListItem","position":3,"name":"False security: Dashy's client-side authentication"}]}
```

