A production source map is publicly available
A public source map makes application source code and internal paths easier to inspect. This example did not contain credentials.
Keep production source maps private. Upload them directly to your error tracker, remove public copies, and verify that the URL is no longer accessible.
Source exposure confirmed. Severity depends on what the map reveals; no credential leak is asserted here.
The production JavaScript references a source map that responds without authentication and includes original source content.
GET /assets/app.js.map
Authentication: none
Observed: 200 OK
sourcesContent: presentOn the identified deployed fix, repeat the unauthenticated source-map request and confirm original source content is no longer publicly served. Check that private error-tracker uploads still work.
Example outcome record: verified closed, still reproduced, or inconclusive, with environment and coverage notes. These are acceptance criteria, not a completed retest.